Executive brief
A vulnerability exists in the Linux kernel's Read-Copy Update (RCU) mechanism, which manages how the system handles shared data. Under specific conditions, a data race can occur when the system attempts to track the end of certain internal operations. This could potentially allow a local attacker to cause system instability or gain unauthorized access to sensitive information.
Technical details
A data race exists in the Linux kernel's RCU implementation between rcu_preempt_deferred_qs_handler() and rcu_read_unlock_special(). On kernels built with CONFIG_IRQ_WORK=y, the irq-work handler (which runs with interrupts enabled) can be interrupted by a handler containing an RCU read-side critical section. This leads to concurrent access to the 'defer_qs_iw_pending' field in the per-CPU rcu_data structure. An attacker with local access could exploit this race condition to cause kernel memory corruption or a system crash. The fix involves disabling interrupts across the portion of the handler that updates the affected field.
Affected products
- Linux Linux Kernel 5.3 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-04-24: patched: Initial patch authored by Paul E. McKenney
- 2025-09-11: advisory: CVE-2025-39749 published
References
- https://git.kernel.org/stable/c/0ad84d62217488e679ecc90e8628980dcc003de3
- https://git.kernel.org/stable/c/55e11f6776798b27cf09a7aa0d718415d4fc9cf5
- https://git.kernel.org/stable/c/74f58f382a7c8333f8d09701aefaa25913bdbe0e
- https://git.kernel.org/stable/c/90c09d57caeca94e6f3f87c49e96a91edd40cbfd
- https://git.kernel.org/stable/c/90de9c94ea72327cfa9c2c9f6113c23a513af60b
- https://git.kernel.org/stable/c/b55947b725f190396f475d5d0c59aa855a4d8895
- https://git.kernel.org/stable/c/b5de8d80b5d049f051b95d9b1ee50ae4ab656124