Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-39749

23
FAUCET Score

CVE-2025-39749 is a data race vulnerability in the Linux kernel's RCU (Read-Copy-Update) mechanism, specifically affecting the ->defer_qs_iw_pending field in the rcu_data structure. This flaw occurs when rcu_read_unlock_special() and rcu_preempt_deferred_qs_handler() attempt to access and modify this field concurrently, particularly in kernels configured with CONFIG_IRQ_WORK=y or rcutree.use_softirq=y. The vulnerability impacts various Linux distributions, including Debian and Ubuntu. The vulnerability has a CVSSv3.1 score of 7.0 (HIGH), indicating a local attack vector with high impact on confidentiality, integrity, and availability, but with high attack complexity and requiring low privileges. The data race can lead to system instability or crashes, as evidenced by KCSAN splats. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Despite this, the vulnerability has garnered significant community discussion and media coverage, suggesting a recognized importance within the cybersecurity community.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.3, < 5.4.297CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5, < 5.10.241CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.190CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.149CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.2, < 6.6.103CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.0HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
5.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 23rd percentile among its peer group of 1,525 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

microsoftpatch availablevia msrc
Product: 20412-17084Fixed in: 6.6.104.2-1
microsoftpatch availablevia msrc
Product: 17087-17086Fixed in: 5.15.200.1-1
microsoftpatch availablevia msrc
Product: azl3 kernel 6.6.96.2-2 on Azure Linux 3.0Fixed in: 6.6.104.2-1
microsoftpatch availablevia msrc
Product: cbl2 kernel 5.15.186.1-1 on CBL Mariner 2.0Fixed in: 5.15.200.1-1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1

Vendor Advisories (7)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
redhatCVE-2025-39749

kernel: rcu: Protect ->defer_qs_iw_pending from data race

Sep 11, 2025
microsoft2025-Sep/CVE-2025-39749Moderate

rcu: Protect ->defer_qs_iw_pending from data race

Sep 9, 2025

References

cert-portal.siemens.com / productcert/html/ssa-032379.html
git.kernel.org / stable/c/0ad84d62217488e679ecc90e8628980dcc003de3
Patch
git.kernel.org / stable/c/55e11f6776798b27cf09a7aa0d718415d4fc9cf5
Patch
git.kernel.org / stable/c/74f58f382a7c8333f8d09701aefaa25913bdbe0e
Patch
git.kernel.org / stable/c/90c09d57caeca94e6f3f87c49e96a91edd40cbfd
Patch
git.kernel.org / stable/c/90de9c94ea72327cfa9c2c9f6113c23a513af60b
Patch
git.kernel.org / stable/c/b55947b725f190396f475d5d0c59aa855a4d8895
Patch
git.kernel.org / stable/c/b5de8d80b5d049f051b95d9b1ee50ae4ab656124
Patch
git.kernel.org / stable/c/e35e711c78c8a4c43330c0dcb1c4d507a19c20f4
Patch
git.kernel.org / stable/c/f937759c7432d6151b73e1393b6517661813d506
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00007.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Mailing ListThird Party Advisory