Executive brief
A vulnerability in the Linux kernel's network bridging component can allow a local user to cause a system-wide freeze or 'soft lockup.' By setting extremely large values for multicast query intervals, a timer overflow occurs that puts the processor into an infinite loop. This results in a denial-of-service, making the affected system unresponsive and disrupting all hosted operations and services.
Technical details
A vulnerability exists in the Linux kernel bridge multicast implementation (br_multicast.c) where setting 'multicast_query_interval' or 'multicast_startup_query_interval' to a very large value (e.g., 0xffffffffffffffff) causes an integer overflow in the local 'time' variable within br_multicast_send_query(). When the overflowed value is smaller than the current jiffies, the timer expires immediately and re-triggers itself in a loop, leading to a CPU soft lockup. The fix introduces a maximum allowable interval (24 hours) to prevent the overflow. This requires local administrative privileges to modify sysfs bridge parameters.
Affected products
- Linux Linux Kernel 6.16.0+; fixed in 34171b9e, 43e281fd, 5bf5fce8, 96476b04, bdb19cd0, d1547bf4
- Siemens SIMATIC CN 4100 < V5.0
- Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5
- Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.5
- Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.5
Timeline
- 2025-08-13: patched: Initial fix authored by Wang Liang
- 2025-09-11: advisory: CVE published by NVD
References
- https://git.kernel.org/stable/c/34171b9e53bd1dc264f5556579f2b04f04435c73
- https://git.kernel.org/stable/c/43e281fde5e76a866a4d10780c35023f16c0e432
- https://git.kernel.org/stable/c/5bf5fce8a0c2a70d063af778fdb5b27238174cdd
- https://git.kernel.org/stable/c/96476b043efb86a94f2badd260f7f99c97bd5893
- https://git.kernel.org/stable/c/bdb19cd0de739870bb3494c815138b9dc30875c4
- https://git.kernel.org/stable/c/d1547bf460baec718b3398365f8de33d25c5f36f
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html