CVE-2025-39703
A critical bug in the Linux kernel can cause a crash when it receives a corrupted HSR frame that does not have enough space for the HSR tag. The crash occurs in the networking stack and can bring the system down. The issue is triggered by a malformed packet that can be sent over the network.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel versions 5.13 and 6.17 (and earlier) on systems that use HSR (High‑availability Seamless Redundancy) networking, including Debian 11.0. Any host running a vulnerable kernel and configured for HSR is at risk.
Real-world impact
An attacker could send a specially crafted HSR frame to a vulnerable system, causing the kernel to panic and the machine to reboot or become unresponsive. This denial‑of‑service condition could be used to disrupt critical services or as a stepping stone to further attacks if the crash can be leveraged.
Why this severity
The CVSS score of 9.8 reflects that the vulnerability is exploitable over the network, requires no privileges, and can compromise confidentiality, integrity, and availability, leading to a kernel panic. The attack vector is network‑based, the attack complexity is low, and the impact is complete.
What to do about it
- 01Upgrade the Linux kernel to a version that includes the fix for CVE-2025-39703.
- 02Reboot the system to load the new kernel.
NVD-referenced vendor advisory
Timeline
- Sep 5, 2025 · Sep 5, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 6h agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 3h agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- git.kernel.org/stable/c/3ae272ab523dd6bdc2…patch
- git.kernel.org/stable/c/61009439e4bd8d74e7…patch
- git.kernel.org/stable/c/7af76e9d18a9fd6f86…patch
- git.kernel.org/stable/c/8d9bc4a375a1ba05f7…patch
- git.kernel.org/stable/c/acd69b597bd3f76d3b…patch
- git.kernel.org/stable/c/b117c41b00902c1a7e…patch
- git.kernel.org/stable/c/b640188b8a6690e685…patch
- lists.debian.org/debian-lts-announce/2025/10…mailing listthird party advisory
- lists.debian.org/debian-lts-announce/2025/10…mailing listthird party advisory
- cert-portal.siemens.com/productcert/html/ssa-032379…