CVE-2025-39955
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/10/2025
Last modified:
09/10/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect().<br />
<br />
syzbot reported the splat below where a socket had tcp_sk(sk)->fastopen_rsk<br />
in the TCP_ESTABLISHED state. [0]<br />
<br />
syzbot reused the server-side TCP Fast Open socket as a new client before<br />
the TFO socket completes 3WHS:<br />
<br />
1. accept()<br />
2. connect(AF_UNSPEC)<br />
3. connect() to another destination<br />
<br />
As of accept(), sk->sk_state is TCP_SYN_RECV, and tcp_disconnect() changes<br />
it to TCP_CLOSE and makes connect() possible, which restarts timers.<br />
<br />
Since tcp_disconnect() forgot to clear tcp_sk(sk)->fastopen_rsk, the<br />
retransmit timer triggered the warning and the intended packet was not<br />
retransmitted.<br />
<br />
Let&#39;s call reqsk_fastopen_remove() in tcp_disconnect().<br />
<br />
[0]:<br />
WARNING: CPU: 2 PID: 0 at net/ipv4/tcp_timer.c:542 tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7))<br />
Modules linked in:<br />
CPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 6.17.0-rc5-g201825fb4278 #62 PREEMPT(voluntary)<br />
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014<br />
RIP: 0010:tcp_retransmit_timer (net/ipv4/tcp_timer.c:542 (discriminator 7))<br />
Code: 41 55 41 54 55 53 48 8b af b8 08 00 00 48 89 fb 48 85 ed 0f 84 55 01 00 00 0f b6 47 12 3c 03 74 0c 0f b6 47 12 3c 04 74 04 90 0b 90 48 8b 85 c0 00 00 00 48 89 ef 48 8b 40 30 e8 6a 4f 06 3e<br />
RSP: 0018:ffffc900002f8d40 EFLAGS: 00010293<br />
RAX: 0000000000000002 RBX: ffff888106911400 RCX: 0000000000000017<br />
RDX: 0000000002517619 RSI: ffffffff83764080 RDI: ffff888106911400<br />
RBP: ffff888106d5c000 R08: 0000000000000001 R09: ffffc900002f8de8<br />
R10: 00000000000000c2 R11: ffffc900002f8ff8 R12: ffff888106911540<br />
R13: ffff888106911480 R14: ffff888106911840 R15: ffffc900002f8de0<br />
FS: 0000000000000000(0000) GS:ffff88907b768000(0000) knlGS:0000000000000000<br />
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033<br />
CR2: 00007f8044d69d90 CR3: 0000000002c30003 CR4: 0000000000370ef0<br />
Call Trace:<br />
<br />
tcp_write_timer (net/ipv4/tcp_timer.c:738)<br />
call_timer_fn (kernel/time/timer.c:1747)<br />
__run_timers (kernel/time/timer.c:1799 kernel/time/timer.c:2372)<br />
timer_expire_remote (kernel/time/timer.c:2385 kernel/time/timer.c:2376 kernel/time/timer.c:2135)<br />
tmigr_handle_remote_up (kernel/time/timer_migration.c:944 kernel/time/timer_migration.c:1035)<br />
__walk_groups.isra.0 (kernel/time/timer_migration.c:533 (discriminator 1))<br />
tmigr_handle_remote (kernel/time/timer_migration.c:1096)<br />
handle_softirqs (./arch/x86/include/asm/jump_label.h:36 ./include/trace/events/irq.h:142 kernel/softirq.c:580)<br />
irq_exit_rcu (kernel/softirq.c:614 kernel/softirq.c:453 kernel/softirq.c:680 kernel/softirq.c:696)<br />
sysvec_apic_timer_interrupt (arch/x86/kernel/apic/apic.c:1050 (discriminator 35) arch/x86/kernel/apic/apic.c:1050 (discriminator 35))<br />
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/17d699727577814198d744d6afe54735c6b54c99
- https://git.kernel.org/stable/c/33a4fdf0b4a25f8ce65380c3b0136b407ca57609
- https://git.kernel.org/stable/c/45c8a6cc2bcd780e634a6ba8e46bffbdf1fc5c01
- https://git.kernel.org/stable/c/7ec092a91ff351dcde89c23e795b73a328274db6
- https://git.kernel.org/stable/c/a4378dedd6e07e62f2fccb17d78c9665718763d0
- https://git.kernel.org/stable/c/ae313d14b45eca7a6bb29cb9bf396d977e7d28fb
- https://git.kernel.org/stable/c/dfd06131107e7b699ef1e2a24ed2f7d17c917753
- https://git.kernel.org/stable/c/fa4749c065644af4db496b338452a69a3e5147d9



