Junglewise Threat Intelligence

CVE-2025-39681: Linux Kernel division by zero in Hygon CPU initialization

CVE-2025-39681 · Severity: medium · CVSS 5.5 · Published 2025-09-05

Technologies: Siemens SIMATIC CN 4100, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's handling of Hygon processors can cause systems to crash during the startup process. This issue occurs because the system fails to properly initialize certain processor monitoring features, leading to a critical error. For businesses, this could result in a denial-of-service scenario where affected hardware fails to boot or becomes unstable, impacting operational availability.

Technical details

A regression was introduced in the Linux kernel when resctrl_cpu_detect() was moved to vendor-specific BSP initialization helpers, but was omitted from the Hygon-specific implementation. On Hygon systems supporting X86_FEATURE_CQM, this results in boot_cpu_data.x86_cache_occ_scale remaining uninitialized (zero). When get_rdt_mon_resources() subsequently attempts to calculate mon_l3_config using this value, it triggers a division-by-zero fault during the early booting stage. The vulnerability is resolved by adding the missing resctrl_cpu_detect() call to the Hygon bsp_init helper. Patches have been released for various stable kernel branches.

Affected products

  • Linux Linux Kernel 923f3a2b48bd to 62f12cde10118253348a7540e85606869bd69432
  • Siemens SIMATIC CN 4100 < V5.0
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6

Timeline

  • 2025-06-23: disclosed: Initial patch submission by Tianxiang Peng
  • 2025-09-04: patched: Patch committed to Linux stable tree
  • 2025-09-05: advisory: CVE published

References

Related threats