CVE-2025-39829

MEDIUM

Linux Kernel - Denial of Service via Missing Notifier Unregistration in ftrace_suspend_notifier_call

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: trace/fgraph: Fix the warning caused by missing unregister notifier This warning was triggered during testing on v6.16: notifier callback ftrace_suspend_notifier_call already registered WARNING: CPU: 2 PID: 86 at kernel/notifier.c:23 notifier_chain_register+0x44/0xb0 ... Call Trace: <TASK> blocking_notifier_chain_register+0x34/0x60 register_ftrace_graph+0x330/0x410 ftrace_profile_write+0x1e9/0x340 vfs_write+0xf8/0x420 ? filp_flush+0x8a/0xa0 ? filp_close+0x1f/0x30 ? do_dup2+0xaf/0x160 ksys_write+0x65/0xe0 do_syscall_64+0xa4/0x260 entry_SYSCALL_64_after_hwframe+0x77/0x7f When writing to the function_profile_enabled interface, the notifier was not unregistered after start_graph_tracing failed, causing a warning the next time function_profile_enabled was written. Fixed by adding unregister_pm_notifier in the exception path.

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (12)
linux/Kernel 2.6.30 - 6.12.45linux
linux/Kernel 6.13.0 - 6.16.5linux
Linux/Linux < 2.6.30
Linux/Linux 2.6.30
Linux/Linux 4a2b8dda3f8705880ec7408135645602d5590f51 - 000aa47a51233fd38a629b029478e0278e1e9fbe
Linux/Linux 4a2b8dda3f8705880ec7408135645602d5590f51 - 2a2deb9f8df70480050351ac27041f19bb9e718b
Linux/Linux 4a2b8dda3f8705880ec7408135645602d5590f51 - edede7a6dcd7435395cf757d053974aaab6ab1c2
Linux/Linux 6.12.45 - 6.12.*
Linux/Linux 6.16.5 - 6.16.*
Linux/Linux 6.17
... and 2 more
Published Sep 16, 2025
Tracked Since Feb 18, 2026