Junglewise Threat Intelligence

CVE-2025-39773: Linux Kernel soft lockup in bridge multicast query expired

CVE-2025-39773 · Severity: medium · CVSS 5.5 · Published 2025-09-11

Technologies: Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC CN 4100, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's network bridging component can allow a local user to cause a system-wide freeze or 'soft lockup.' By setting extremely large values for multicast query intervals, a timer overflow occurs that puts the processor into an infinite loop. This results in a denial-of-service, making the affected system unresponsive and disrupting all hosted operations and services.

Technical details

A vulnerability exists in the Linux kernel bridge multicast implementation (br_multicast.c) where setting 'multicast_query_interval' or 'multicast_startup_query_interval' to a very large value (e.g., 0xffffffffffffffff) causes an integer overflow in the local 'time' variable within br_multicast_send_query(). When the overflowed value is smaller than the current jiffies, the timer expires immediately and re-triggers itself in a loop, leading to a CPU soft lockup. The fix introduces a maximum allowable interval (24 hours) to prevent the overflow. This requires local administrative privileges to modify sysfs bridge parameters.

Affected products

  • Linux Linux Kernel 6.16.0+; fixed in 34171b9e, 43e281fd, 5bf5fce8, 96476b04, bdb19cd0, d1547bf4
  • Siemens SIMATIC CN 4100 < V5.0
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.5
  • Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP V3.1.5
  • Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP V3.1.5

Timeline

  • 2025-08-13: patched: Initial fix authored by Wang Liang
  • 2025-09-11: advisory: CVE published by NVD

References

Related threats