Executive brief
A vulnerability in the Linux kernel's memory management system could allow a local user to cause a system crash. The issue occurs when specific debugging features are enabled, leading to a circular locking dependency (deadlock) during memory allocation. This results in a complete system hang or 'kernel oops,' impacting the availability of the affected server or workstation.
Technical details
A lock recursion vulnerability exists in the Linux kernel's SLUB allocator within the set_track_prepare() function. When CONFIG_DEBUG_OBJECTS_TIMERS is enabled, set_track_prepare() may be called while holding the hrtimer_bases lock. If the function triggers a kswapd wakeup for memory reclamation, it may attempt to acquire the same hrtimer lock, resulting in a deadlock. The fix involves masking out reclamation flags (__GFP_KSWAPD_RECLAIM and __GFP_DIRECT_RECLAIM) during these specific allocation paths to prevent implicit kswapd wakeups. This issue affects systems where stack depot is used to save stack traces in objects.
Affected products
- Linux Linux Kernel versions from 5.19 up to 6.1.151, 6.2 up to 6.6.105, 6.7 up to 6.12.46, 6.13 up to 6.16.6
Timeline
- 2025-09-19: disclosed
- 2025-09-19: advisory
References
- https://git.kernel.org/stable/c/243b705a90ed8449f561a271cf251fd2e939f3db
- https://git.kernel.org/stable/c/522ffe298627cfe72539d72167c2e20e72b5e856
- https://git.kernel.org/stable/c/850470a8413a8a78e772c4f6bd9fe81ec6bd5b0f
- https://git.kernel.org/stable/c/994b03b9605d36d814c611385fbf90ca6db20aa8
- https://git.kernel.org/stable/c/eb3240ffd243bfb8b1e9dc568d484ecf9fd660ab
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html