Junglewise Threat Intelligence

CVE-2025-39715: Linux Kernel PA-RISC insufficient read access validation in LWS gateway calls

CVE-2025-39715 · Severity: medium · CVSS 5.5 · Published 2025-09-05

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel for systems using the PA-RISC architecture could allow a local user to bypass certain memory protections. Specifically, the system fails to properly check read permissions when performing certain low-level synchronization operations. This could potentially be used by an attacker to cause a system crash or interfere with memory that should be restricted.

Technical details

A vulnerability exists in the PA-RISC architecture's implementation of Light-Weight Syscall (LWS) gateway calls in the Linux kernel. The kernel uses 'ldw' and 'stbys,e' instructions to trigger memory reference interruptions; however, because the kernel and gateway page execute at privilege level 0, read access interruptions (which only trigger at levels 2 and 3) are never generated. This allows user-space code to execute LWS compare-and-swap operations on memory addresses that should be read-protected at the user privilege level (PRIV_USER). The fix introduces explicit 'proberi' instructions to verify read access rights at privilege level 3 before proceeding with the operation.

Affected products

  • Linux Linux Kernel 5.12 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.44, 6.13 to 6.16.4

Timeline

  • 2025-09-05: disclosed
  • 2025-09-05: advisory

References

Related threats