Junglewise Threat Intelligence

CVE-2025-39749: Linux Kernel data race in RCU deferred quiescent state handler

CVE-2025-39749 · Severity: high · CVSS 7 · Published 2025-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's Read-Copy Update (RCU) mechanism, which manages how the system handles shared data. Under specific conditions, a data race can occur when the system attempts to track the end of certain internal operations. This could potentially allow a local attacker to cause system instability or gain unauthorized access to sensitive information.

Technical details

A data race exists in the Linux kernel's RCU implementation between rcu_preempt_deferred_qs_handler() and rcu_read_unlock_special(). On kernels built with CONFIG_IRQ_WORK=y, the irq-work handler (which runs with interrupts enabled) can be interrupted by a handler containing an RCU read-side critical section. This leads to concurrent access to the 'defer_qs_iw_pending' field in the per-CPU rcu_data structure. An attacker with local access could exploit this race condition to cause kernel memory corruption or a system crash. The fix involves disabling interrupts across the portion of the handler that updates the affected field.

Affected products

  • Linux Linux Kernel 5.3 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2

Timeline

  • 2025-04-24: patched: Initial patch authored by Paul E. McKenney
  • 2025-09-11: advisory: CVE-2025-39749 published

References

Related threats