Junglewise Threat Intelligence

CVE-2025-39736: Linux Kernel deadlock in kmemleak mem_pool_alloc

CVE-2025-39736 · Severity: medium · CVSS 5.5 · Published 2025-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's memory leak detection tool (kmemleak) can cause the entire system to freeze or crash (deadlock). This occurs when the system attempts to log a warning message while already holding a critical internal lock, particularly when network-based logging is enabled. An exploit of this flaw would result in a total loss of system availability, requiring a hard reboot.

Technical details

A lock inversion deadlock exists in mm/kmemleak.c within the mem_pool_alloc() function. When the memory pool is exhausted, the kernel calls pr_warn_once() while holding the kmemleak_lock. If netpoll/netconsole is enabled, this warning triggers a network transmission that calls __alloc_skb(), which in turn calls back into kmemleak code (__create_object) and attempts to reacquire the same kmemleak_lock. This circular dependency results in a kernel deadlock. The fix involves moving the warning trigger outside of the critical section protected by the spinlock.

Affected products

  • Linux Linux Kernel 5.4 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-07-31: other: Patch submitted by Breno Leitao
  • 2025-08-05: patched: Committed to mainline kernel
  • 2025-09-11: disclosed: CVE published

References