Junglewise Threat Intelligence

CVE-2025-39815: Linux Kernel RISC-V KVM stack overflow in vlenb loading

CVE-2025-39815 · Severity: high · CVSS 7.8 · Published 2025-09-16

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's virtualization component for RISC-V processors could allow a local user to cause a system crash or potentially gain unauthorized access. The issue occurs when the system handles specific hardware configuration data, leading to a memory error. This affects systems using KVM (Kernel-based Virtual Machine) on RISC-V architecture.

Technical details

A stack-based buffer overflow exists in arch/riscv/kvm/vcpu_vector.c within the kvm_riscv_vcpu_set_reg_vector function. The vulnerability is caused by a lack of size validation when copying the 'vlenb' Vector Control and Status Register (CSR) value from userspace. An attacker can provide up to 2048 bits of data into a stack buffer sized for a single 'unsigned long' (xlen bits), leading to a stack overrun. This requires local access with permissions to interact with KVM VCPU registers. Patches have been released in stable kernel versions 6.12.45, 6.16.5, and 6.17.

Affected products

  • Linux Linux Kernel 6.8 to 6.12.45, 6.13 to 6.16.5

Timeline

  • 2025-08-05: patched: Initial patch authored by Radim Krčmář
  • 2025-09-16: disclosed: CVE published by kernel.org

References

Related threats