Executive brief
A vulnerability in the Linux kernel's file management system could allow a local user to crash or destabilize the system. By requesting an extremely high number of simultaneous open files, a process can force the kernel to attempt a massive memory allocation that exceeds internal limits. This results in a kernel warning and potential resource exhaustion, impacting the availability of the operating system.
Technical details
A vulnerability exists in the Linux kernel's 'fs/file.c' component within the 'alloc_fdtable()' function. When 'sysctl_nr_open' is set to a high value (often done automatically by systemd), a local process can trigger an allocation request exceeding INT_MAX by calling functions like 'dup2()' with a high file descriptor index. Because 'kvmalloc()' and 'kvmalloc_array()' enforce an INT_MAX limit and emit a warning when exceeded (unless __GFP_NOWARN is set), this results in a kernel WARNING in 'mm/slub.c'. An attacker can exploit this to trigger impractical memory allocations (e.g., >8GB), leading to local denial-of-service conditions. The fix introduces a check in 'alloc_fdtable()' to ensure requested allocations do not exceed INT_MAX, returning -EMFILE instead.
Affected products
- Linux Linux Kernel All versions prior to the 2025-07-08 patch (including various stable branches)
- Siemens SIMATIC CN 4100 versions prior to V5.0
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5 and later
Timeline
- 2025-06-29: disclosed: Initial patch submitted by Sasha Levin
- 2025-07-08: patched: Patch committed to mainline kernel by Christian Brauner
- 2025-09-11: advisory: CVE published in NVD
References
- https://git.kernel.org/stable/c/04a2c4b4511d186b0fce685da21085a5d4acd370
- https://git.kernel.org/stable/c/237e416eb62101f21b28c9e6e564d10efe1ecc6f
- https://git.kernel.org/stable/c/628fc28f42d979f36dbf75a6129ac7730e30c04e
- https://git.kernel.org/stable/c/749528086620f8012b83ae032a80f6ffa80c45cd
- https://git.kernel.org/stable/c/9f61fa6a2a89a610120bc4e5d24379c667314b5c
- https://git.kernel.org/stable/c/b4159c5a90c03f8acd3de345a7f5fc63b0909818
- https://git.kernel.org/stable/c/d4f9351243c17865a8cdbe6b3ccd09d0b13a7bcc