Executive brief
A vulnerability in the Linux kernel's support for Rockchip processors can cause the system to hang or become unresponsive during startup. This occurs due to a synchronization issue when the main processor attempts to initialize secondary processor cores. An exploit could lead to a complete denial of service, preventing the device from functioning or booting correctly.
Technical details
A race condition exists in the Rockchip SMP (Symmetric Multi-Processing) initialization code within the Linux kernel. During the boot process, the primary CPU writes trampoline code to SRAM to bring up secondary CPUs. On certain hardware like the RK3188, this write occurs while secondary CPUs are already powered on, potentially causing them to execute the trampoline code prematurely or unexpectedly, leading to a kernel hang. The fix involves reordering the initialization sequence so that SRAM is prepared only after all secondary CPUs are confirmed to be powered down. This is a local denial-of-service vulnerability.
Affected products
- Linux Linux Kernel 3.19 to 5.4.297, 5.5 to 5.10.241, 5.11 to 5.15.190, 5.16 to 6.1.149, 6.2 to 6.6.103, 6.7 to 6.12.43, 6.13 to 6.15.11, 6.16 to 6.16.2
Timeline
- 2025-09-11: disclosed
- 2025-09-11: advisory
- 2025-08-20: patched: Initial patch commits in stable branches
References
- https://git.kernel.org/stable/c/0223a3683d502b7e5eb2eb4ad7e97363fa88d531
- https://git.kernel.org/stable/c/1eb67589a7e091b1e5108aab72fddbf4dc69af2c
- https://git.kernel.org/stable/c/265583266d93db4ff83d088819b1f63fdf0131db
- https://git.kernel.org/stable/c/3c6bf7a324b8995b9c7d790c8d2abf0668f51551
- https://git.kernel.org/stable/c/47769dab9073a73e127aa0bfd0ba4c51eaccdc33
- https://git.kernel.org/stable/c/7cdb433bb44cdc87dc5260cdf15bf03cc1cd1814
- https://git.kernel.org/stable/c/888a453c2a239765a7ab4de8a3cedae2e3802528