Executive brief
A vulnerability was identified in the Linux kernel's smc91x network driver when used with real-time (PREEMPT_RT) configurations. This flaw can cause the system to leak atomic locks or RCU states, potentially leading to system instability or a crash. In practice, this could result in a denial-of-service, impacting the availability of systems relying on this specific hardware driver.
Technical details
The vulnerability exists in the smc91x Ethernet driver (drivers/net/ethernet/smsc/smc91x.c) when built with PREEMPT_RT. The root cause is an inconsistency in how interrupts are handled: smc_special_trylock() manually disables interrupts using local_irq_save(), but the corresponding smc_special_unlock() uses spin_unlock_irqrestore(), which may fail to properly restore the interrupt state or RCU context on real-time kernels when the softirq disable count reaches zero. This leads to a 'workqueue leaked atomic' kernel splat. The fix replaces the manual IRQ management in the trylock macro with the standard spin_trylock_irqsave() primitive. Patch availability is confirmed across multiple stable kernel branches.
Affected products
- Linux Linux Kernel 5.15 to 5.15.198, 6.1 to 6.1.160, 6.6 to 6.6.120, 6.12 to 6.12.10, 6.13 to 6.13.1
Timeline
- 2025-12-17: disclosed: Initial patch submission by Yeoreum Yun
- 2025-12-23: patched: Mainline kernel patch committed
- 2026-01-14: advisory: CVE-2025-71132 published
References
- https://git.kernel.org/stable/c/1c4cb705e733250d13243f6a69b8b5a92e39b9f6
- https://git.kernel.org/stable/c/36561b86cb2501647662cfaf91286dd6973804a6
- https://git.kernel.org/stable/c/6402078bd9d1ed46e79465e1faaa42e3458f8a33
- https://git.kernel.org/stable/c/9d222141b00156509d67d80c771fbefa92c43ace
- https://git.kernel.org/stable/c/b6018d5c1a8f09d5efe4d6961d7ee45fdf3a7ce3
- https://git.kernel.org/stable/c/ef277ae121b3249c99994652210a326b52d527b0