Junglewise Threat Intelligence

CVE-2025-39817: Linux Kernel slab-out-of-bounds read in efivarfs_d_compare

CVE-2025-39817 · Severity: high · CVSS 7.1 · Published 2025-09-16

Technologies: Siemens SIMATIC CN 4100, Linux Kernel. Vendors: Siemens, Linux.

Executive brief

A vulnerability was identified in the Linux kernel's efivarfs file system, which is used to access EFI variables. An attacker with local access could trigger a system crash or potentially access restricted memory by using specially crafted, invalid filenames during file lookups. This could lead to a denial of service or unauthorized information disclosure, impacting the stability and security of the affected system.

Technical details

A slab-out-of-bounds read vulnerability exists in the efivarfs_d_compare function within the Linux kernel's efivarfs file system. The root cause is a missing length check: if a dentry name length is less than EFI_VARIABLE_GUID_LEN, the calculated 'guid' offset becomes negative, leading to an out-of-bounds memory access during a memcmp operation. This race condition can be triggered by parallel lookups where an invalid dentry is temporarily added to the hash list and subsequently retrieved by a concurrent process. An attacker with local privileges can exploit this to cause a kernel panic (DoS) or read sensitive kernel memory. The issue has been patched in multiple stable kernel branches by adding a check to ensure the filename length is sufficient before performing the comparison.

Affected products

  • Linux Linux Kernel 6.6, 6.1, 5.15, 5.10, 5.4, 4.19, 4.14, 4.9
  • Siemens SIMATIC CN 4100 < V5.0

Timeline

  • 2025-08-27: patched: Initial patch authored
  • 2025-09-16: disclosed: CVE published

References

Related threats