Executive brief
A vulnerability in the Linux kernel's networking subsystem can cause a system to become unresponsive. The issue occurs when the system incorrectly handles memory limits for internal communication, leading to an infinite loop that consumes processor resources. This can result in a complete denial of service, impacting the availability of the affected device or server.
Technical details
A vulnerability classified as CWE-835 (Loop with Unreachable Exit Condition) exists in the Linux kernel's netlink implementation. The function netlink_attachskb() fails to account for a specific edge case where the socket's receive memory allocation (sk_rmem_alloc) plus the buffer size (skb->truesize) exactly equals the receive buffer limit (sk_rcvbuf). When this condition is met, the function neither accepts the packet nor triggers a wait/reschedule, resulting in an infinite retry loop. This leads to RCU CPU stalls and a local denial of service. The issue was introduced during a code restructuring and has been fixed by updating the boundary check from less-than to less-than-or-equal-to.
Affected products
- Linux Linux Kernel Fixed in 5.10.240, 5.15.166, 6.1.107, 6.6.48, 6.10.7, 6.11-rc5
- Siemens SIMATIC CN 4100 Versions prior to V5.0
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5 and later
Timeline
- 2025-07-28: disclosed: Initial patch submitted by Fedor Pchelkin
- 2025-08-28: patched: Patches merged into stable kernel branches
- 2025-09-04: advisory: CVE-2025-38727 published
References
- https://git.kernel.org/stable/c/346c820ef5135cf062fa3473da955ef8c5fb6929
- https://git.kernel.org/stable/c/44ddd7b1ae0b7edb2c832eb16798c827a05e58f0
- https://git.kernel.org/stable/c/47d49fd07f86d1f55ea1083287303d237e9e0922
- https://git.kernel.org/stable/c/6bee383ff83352a693d03efdf27cdd80742f71b2
- https://git.kernel.org/stable/c/759dfc7d04bab1b0b86113f1164dc1fec192b859
- https://git.kernel.org/stable/c/78fcd69d55c5f11d7694c547eca767a1cfd38ec4
- https://git.kernel.org/stable/c/d42b71a34f6b8a2d5c53df81169b03b8d8b5cf4e