Junglewise Threat Intelligence

CVE-2025-39742: Linux Kernel RDMA hfi1 divide-by-zero in find_hw_thread_mask

CVE-2025-39742 · Severity: medium · CVSS 5.5 · Published 2025-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's RDMA (Remote Direct Memory Access) subsystem that could allow a local user to cause a system crash. The issue occurs during specific processor affinity calculations, where a mathematical error (division by zero) can trigger a kernel panic. This primarily impacts system availability, potentially leading to a denial-of-service condition on affected servers.

Technical details

A divide-by-zero vulnerability exists in the find_hw_thread_mask() function within the drivers/infiniband/hw/hfi1/affinity.c component of the Linux kernel. The root cause is a logic error where the code performs a division using 'affinity->num_core_siblings' as a divisor before verifying that the value is non-zero. A local attacker with sufficient privileges to interact with RDMA interfaces could potentially trigger this condition, resulting in a kernel oops or panic (Denial of Service). The fix involves reordering the validation check to ensure the divisor is non-zero before the arithmetic operation is performed. Patches have been backported to multiple stable kernel branches including 5.4.y, 5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.12.y, 6.15.y, and 6.16.y.

Affected products

  • Linux Linux Kernel 4.8 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-09-11: disclosed: Initial disclosure of the vulnerability and CVE assignment.
  • 2025-08-28: patched: Fix committed to the Linux stable tree.

References

Related threats