Executive brief
A security vulnerability has been identified in the Linux kernel's Pressure Stall Information (PSI) monitoring system, which tracks system resource pressure. A local attacker could exploit a race condition to cause a system crash or potentially execute unauthorized code by manipulating how these monitoring files are opened and closed. This issue primarily affects system stability and could be used to gain deeper access to the underlying operating system.
Technical details
A use-after-free (UAF) vulnerability exists in the kernfs subsystem of the Linux kernel. The root cause is a race condition between epoll monitoring and the release of PSI (Pressure Stall Information) triggers. When a cgroup pressure file is disabled, the kernel releases PSI triggers and frees the associated private data (of->priv). However, if an epoll instance still holds a reference to the file and continues polling, re-enabling the monitoring can lead to an access of the previously freed memory in psi_trigger_poll. An attacker with local access can trigger this by rapidly toggling cgroup pressure monitoring while polling the file descriptor. The fix introduces kernfs_get_active_of() to ensure active references are valid and have not been released before proceeding with polling operations.
Affected products
- Linux Linux Kernel 6.1 to 6.1.153, 6.6 to 6.6.107, 6.12 to 6.12.48
Timeline
- 2025-08-22: disclosed: Initial patch submitted by Huawei developers
- 2025-09-06: patched: Patch committed to stable kernel tree
- 2025-09-23: advisory: CVE-2025-39881 published
References
- https://git.kernel.org/stable/c/34d9cafd469c69ad85e6a36b4303c78382cf5c79
- https://git.kernel.org/stable/c/3c9ba2777d6c86025e1ba4186dc5cd930e40ec5f
- https://git.kernel.org/stable/c/7e64474aba78d240f7804f48f2d454dcca78b15f
- https://git.kernel.org/stable/c/854baafc00c433cccbe0ab4231b77aeb9b637b77
- https://git.kernel.org/stable/c/ac5cda4fae8818cf1963317bb699f7f2f85b60af
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html