CVE-2025-39965 is a use-after-free vulnerability in the Linux kernel XFRM/IPsec subsystem. The flaw arises because xfrm_alloc_spi incorrectly permits Security Parameter Index (SPI) value 0 to be used, even though an XFRM state with x->id.spi equal to 0 is intended to represent a state with no SPI assigned. As a result of the affected logic introduced by the duplicate SPI handling changes, XFRM states can be created and inserted into the byspi list with spi==0. Later, __xfrm_state_delete does not remove those states from the byspi list because such entries are not expected to exist there. Subsequent traversal of the byspi list can then dereference freed state objects, producing a use-after-free condition in kernel memory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (PoC) exploit targeting the Linux kernel's XFRM (IPsec) subsystem, likely related to a recent (1-day) vulnerability as referenced in the README. The main files are 'poc.c' and 'read.c', both written in C, which interact with the kernel via netlink sockets to allocate, query, update, and delete Security Associations (SAs) using hardcoded localhost IP addresses (127.0.0.1 and 127.0.0.2). The Makefile provides build instructions, and 'run.sh' demonstrates how to set the necessary capabilities and execute the exploit binary. The exploit requires 'cap_net_admin' privileges, which are set using 'setcap-static'. The code is not a detection script but a functional PoC that manipulates kernel structures, likely to trigger or demonstrate a vulnerability in the XFRM subsystem. No external network endpoints are used; all operations are local to the system. The repository is structured for research and educational purposes, as stated in the README.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.