Junglewise Threat Intelligence

CVE-2025-39737: Linux Kernel soft lockup in kmemleak cleanup

CVE-2025-39737 · Severity: medium · CVSS 5.5 · Published 2025-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's memory leak detection tool (kmemleak) can cause a system to become unresponsive. When the tool attempts to clean up a large number of tracked memory objects, it can monopolize the processor for an extended period, leading to a 'soft lockup.' This primarily affects systems running debug kernels or specific workloads that trigger mass memory object deletion, potentially resulting in a denial-of-service.

Technical details

A soft lockup vulnerability exists in the __kmemleak_do_cleanup() function within mm/kmemleak.c. When kmemleak is disabled (e.g., due to memory pool exhaustion), it attempts to remove and delete all existing kmemleak objects one-by-one in a loop. In environments with a large number of objects (e.g., 40,000+) and the overhead of a debug kernel, the cumulative time spent acquiring and releasing raw_spinlocks in __delete_object() without yielding the CPU causes a watchdog timeout. The fix introduces cond_resched() every 64 iterations to allow the scheduler to run other tasks. This is reachable by local users who can trigger workloads that exhaust the kmemleak memory pool or trigger cleanup.

Affected products

  • Linux Linux Kernel 5.4 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-09-11: advisory: Initial NVD publication
  • 2025-07-28: patched: Fix authored by Waiman Long

References

Related threats