Answer in brief
CVE-2025-39673 records a Unknown severity vulnerability in ppp: fix race conditions in ppp_fill_forward_path. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC CN 4100 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC CN 4100 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f6efc675c9dd8d93f826b79ae7e33e03301db609 <9a1969fbffc1f1900d92d7594b1b7d8d72ef3dc7 || >=f6efc675c9dd8d93f826b79ae7e33e03301db609 <0f1630be6fcca3f0c63e4b242ad202e5cde28a40 || >=f6efc675c9dd8d93f826b79ae7e33e03301db609 <ca18d751bcc9faf5b7e82e9fae1223d103928181 || >=f6efc675c9dd8d93f826b79ae7e33e03301db609 <94731cc551e29511d85aa8dec61a6c071b1f2430 || >=f6efc675c9dd8d93f826b79ae7e33e03301db609 <f97f6475fdcb3c28ff3c55cc4b7bde632119ec08 || >=f6efc675c9dd8d93f826b79ae7e33e03301db609 <0417adf367a0af11adf7ace849af4638cfb573f7 | 9a1969fbffc1f1900d92d7594b1b7d8d72ef3dc7, 0f1630be6fcca3f0c63e4b242ad202e5cde28a40, ca18d751bcc9faf5b7e82e9fae1223d103928181, 94731cc551e29511d85aa8dec61a6c071b1f2430, f97f6475fdcb3c28ff3c55cc4b7bde632119ec08, 0417adf367a0af11adf7ace849af4638cfb573f7 |
| Linux/Linuxgeneric | 5.13 | Not reported |
| Siemens/SIMATIC CN 4100generic | >=0 <V5.0 | V5.0 |
Published upstream
Sep 5, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ppp: fix race conditions in ppp_fill_forward_path ppp_fill_forward_path() has two race conditions: 1. The ppp->channels list can change between list_empty() and list_first_entry(), as ppp_lock() is not held. If the only channel is deleted in ppp_disconnect_channel(), list_first_entry() may access an empty head or a freed entry, and trigger a panic. 2. pch->chan can be NULL. When ppp_unregister_channel() is called, pch->chan is set to NULL before pch is removed from ppp->channels. Fix these by using a lockless RCU approach: - Use list_first_or_null_rcu() to safely test and access the first list entry. - Convert list modifications on ppp->channels to their RCU variants and add synchronize_net() after removal. - Check for a NULL pch->chan before dereferencing it.
Quoted source text, attributed separately from HOL analysis.