Junglewise Threat Intelligence

CVE-2025-39961: Linux kernel race condition in AMD IOMMU page table level increase

CVE-2025-39961 · Severity: high · CVSS 8.8 · Published 2025-10-09

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition was identified in the Linux kernel's AMD IOMMU driver, which manages how hardware devices safely access system memory. Under specific conditions when the system is expanding its memory addressing capabilities, a conflict can occur between different internal processes. This could lead to system instability, failed memory operations, or potential unauthorized access to system resources by a local user.

Technical details

A race condition exists in the AMD IOMMU host page table implementation (drivers/iommu/amd/io_pgtable.c) during dynamic page table level increases. The vulnerability occurs because the unmap path (iommu_v1_unmap_pages) calls fetch_pte(), which reads the page table root and mode without proper synchronization. If increase_address_space() updates these values concurrently, fetch_pte() may read an inconsistent state (e.g., a new root with an old mode), causing it to return NULL and fail the unmap operation. This can trigger WARN_ON logs or higher-level failures. The fix implements a seqcount to ensure atomic-like consistency for lock-free read operations in the fetch_pte() and alloc_pte() paths.

Affected products

  • Linux Linux kernel 4.9.194 to 4.10, 4.14.146 to 4.15, 4.19.75 to 4.20, 5.2.17 to 5.3, 5.3 to 6.13.y

Timeline

  • 2025-09-21: patched: Fix committed to stable tree
  • 2025-10-09: disclosed: CVE published

References

Related threats