Junglewise Threat Intelligence

CVE-2025-39804: Linux Kernel register corruption in ARM64 Poly1305 crypto

CVE-2025-39804 · Severity: high · CVSS 7.5 · Published 2025-09-15

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's cryptographic library for ARM64 processors could lead to system instability or data errors. The issue occurs when the system performs specific security calculations (Poly1305) in a way that accidentally overwrites internal processor data used by other running programs. This can result in incorrect security checks or cause the system to behave unpredictably.

Technical details

A regression in the Linux kernel's ARM64 Poly1305 implementation (introduced in commit a59e5468a921) removed a critical SIMD usability check. When the Poly1305 functions are invoked in contexts where SIMD registers are unusable, the code fails to fall back to non-SIMD paths, leading to the corruption of registers belonging to other tasks or the computation of incorrect Message Authentication Codes (MACs). This is a local vulnerability requiring no special privileges beyond the ability to trigger cryptographic operations. The fix restores the safety check using may_use_simd() in the poly1305-glue.c component. Patches are available in kernel versions 6.16.4 and later.

Affected products

  • Linux Linux Kernel 6.16 to 6.16.4

Timeline

  • 2025-09-15: disclosed
  • 2025-09-15: advisory
  • 2025-08-28: patched: Patch applied to stable tree

References

Related threats