Junglewise Threat Intelligence

CVE-2025-39782: Linux Kernel soft lockup in jbd2_log_do_checkpoint

CVE-2025-39782 · Severity: medium · CVSS 5.5 · Published 2025-09-11

Technologies: Siemens SIMATIC CN 4100, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability in the Linux kernel's journaling block device (jbd2) can cause the system to experience a 'soft lockup,' where the processor becomes stuck in a specific task for an extended period. This component is responsible for ensuring file system integrity during data writes. If exploited, this could lead to a complete system hang or denial of service, impacting the availability of servers and industrial control systems like Siemens SIMATIC controllers.

Technical details

A soft lockup vulnerability exists in the jbd2_log_do_checkpoint() function within the Linux kernel's JBD2 subsystem. The issue stems from the function failing to explicitly call cond_resched() during prolonged operations while contending for the j_list_lock. While the function releases the lock periodically, it relies on sub-functions to trigger rescheduling; if these sub-functions do not sleep, the CPU can remain stuck in a loop for over 150 seconds. A local attacker could potentially trigger this condition to cause a denial of service (system hang). The fix involves adding an explicit cond_resched() call to ensure the scheduler can preempt the task.

Affected products

  • Linux Linux Kernel 6.6.0+; fixed in 6.1.107, 6.6.48, 6.10.7, 6.11-rc5
  • Siemens SIMATIC CN 4100 before V5.0
  • Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP V3.1.6 and later

Timeline

  • 2025-08-12: disclosed: Initial patch submission by Baokun Li
  • 2025-08-28: patched: Commits merged into stable kernel branches
  • 2025-09-11: advisory: CVE-2025-39782 published

References

Related threats