Junglewise Threat Intelligence

CVE-2025-39802: Linux Kernel register corruption in ARM Poly1305 crypto library

CVE-2025-39802 · Severity: high · CVSS 7.5 · Published 2025-09-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's cryptographic library for ARM processors could lead to system instability or data errors. The issue occurs when the system performs specific encryption tasks (Poly1305) in a way that accidentally overwrites data in the processor's registers. This can result in incorrect security calculations or cause other running programs to behave unpredictably or crash.

Technical details

A regression was introduced in the Linux kernel's ARM Poly1305 implementation where a necessary SIMD usability check was removed. When Poly1305 functions are invoked in contexts where SIMD registers are marked as unusable, the code fails to fall back to non-SIMD paths, leading to the corruption of registers belonging to other tasks or the generation of incorrect MACs. The fix restores the safety check using 'may_use_simd()' to ensure SIMD instructions are only executed when the architectural state is safely preserved. This affects ARM-based systems running kernel versions between 6.16 and 6.16.4.

Affected products

  • Linux Linux Kernel 6.16 to 6.16.4

Timeline

  • 2025-07-06: patched: Initial patch authored by Eric Biggers
  • 2025-09-15: disclosed: CVE published

References

Related threats