Junglewise Threat Intelligence

CVE-2025-39756: Linux Kernel denial of service in file descriptor table allocation

CVE-2025-39756 · Severity: medium · CVSS 5.5 · Published 2025-09-11

Technologies: Linux Kernel, Siemens SIMATIC CN 4100, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP. Vendors: Linux, Siemens.

Executive brief

A vulnerability in the Linux kernel's file management system could allow a local user to crash or destabilize the system. By requesting an extremely high number of simultaneous open files, a process can force the kernel to attempt a massive memory allocation that exceeds internal limits. This results in a kernel warning and potential resource exhaustion, impacting the availability of the operating system.

Technical details

A vulnerability exists in the Linux kernel's 'fs/file.c' component within the 'alloc_fdtable()' function. When 'sysctl_nr_open' is set to a high value (often done automatically by systemd), a local process can trigger an allocation request exceeding INT_MAX by calling functions like 'dup2()' with a high file descriptor index. Because 'kvmalloc()' and 'kvmalloc_array()' enforce an INT_MAX limit and emit a warning when exceeded (unless __GFP_NOWARN is set), this results in a kernel WARNING in 'mm/slub.c'. An attacker can exploit this to trigger impractical memory allocations (e.g., >8GB), leading to local denial-of-service conditions. The fix introduces a check in 'alloc_fdtable()' to ensure requested allocations do not exceed INT_MAX, returning -EMFILE instead.

Affected products

  • Linux Linux Kernel All versions prior to the 2025-07-08 patch (including various stable branches)
  • Siemens SIMATIC CN 4100 versions prior to V5.0
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5 and later

Timeline

  • 2025-06-29: disclosed: Initial patch submitted by Sasha Levin
  • 2025-07-08: patched: Patch committed to mainline kernel by Christian Brauner
  • 2025-09-11: advisory: CVE published in NVD

References

Related threats