---
id: CVE-2025-39978
title: 'octeontx2-pf: Fix potential use after free in otx2_tc_add_flow()'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  octeontx2-pf: Fix potential use after free in otx2_tc_add_flow()

  This code calls kfree_rcu(new_node, rcu) and then dereferences "new_node"
  and then dereferences it on …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 68fbff68dbea35f9e6f7649dd22fce492a5aedac <
    5723120423a753a220b8b2954b273838b9d7e74a
  - >-
    Linux >= 68fbff68dbea35f9e6f7649dd22fce492a5aedac <
    df2c071061ed52d2225d97b212d27ecedf456b8a
  - >-
    Linux >= 68fbff68dbea35f9e6f7649dd22fce492a5aedac <
    c41b2941a024d4ec7c768e16ffb10a74b188fced
  - >-
    Linux >= 68fbff68dbea35f9e6f7649dd22fce492a5aedac <
    a8a63f27c3a8a3714210d32b12fd0f16d0337414
  - >-
    Linux >= 68fbff68dbea35f9e6f7649dd22fce492a5aedac <
    d9c70e93ec5988ab07ad2a92d9f9d12867f02c56
  - Linux 5.14
published: '2025-10-15'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:42:40.637Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2025-39978'
references:
  - url: 'https://git.kernel.org/stable/c/5723120423a753a220b8b2954b273838b9d7e74a'
  - url: 'https://git.kernel.org/stable/c/df2c071061ed52d2225d97b212d27ecedf456b8a'
  - url: 'https://git.kernel.org/stable/c/c41b2941a024d4ec7c768e16ffb10a74b188fced'
  - url: 'https://git.kernel.org/stable/c/a8a63f27c3a8a3714210d32b12fd0f16d0337414'
  - url: 'https://git.kernel.org/stable/c/d9c70e93ec5988ab07ad2a92d9f9d12867f02c56'
tags:
  - cve.org
epss: 0.0015
epssPercentile: 0.035
ingestedAt: '2026-09-08T15:33:26.996Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

octeontx2-pf: Fix potential use after free in otx2_tc_add_flow()

This code calls kfree_rcu(new_node, rcu) and then dereferences "new_node"
and then dereferences it on the next line.  Two lines later, we take
a mutex so I don't think this is an RCU safe region.  Re-order it to do
the dereferences before queuing up the free.

## Affected

- `Linux >= 68fbff68dbea35f9e6f7649dd22fce492a5aedac < 5723120423a753a220b8b2954b273838b9d7e74a`
- `Linux >= 68fbff68dbea35f9e6f7649dd22fce492a5aedac < df2c071061ed52d2225d97b212d27ecedf456b8a`
- `Linux >= 68fbff68dbea35f9e6f7649dd22fce492a5aedac < c41b2941a024d4ec7c768e16ffb10a74b188fced`
- `Linux >= 68fbff68dbea35f9e6f7649dd22fce492a5aedac < a8a63f27c3a8a3714210d32b12fd0f16d0337414`
- `Linux >= 68fbff68dbea35f9e6f7649dd22fce492a5aedac < d9c70e93ec5988ab07ad2a92d9f9d12867f02c56`
- `Linux 5.14`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
