CVE-2025-39749
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-39749 is a vulnerability discovered in the Linux kernel affecting systems built with CONFIGIRQWORK=y. The vulnerability was disclosed on September 11, 2025, and involves a data race condition in the RCU (Read-Copy-Update) subsystem (NVD).

Technical details

The vulnerability occurs when rcureadunlock() is invoked within an interrupts-disabled region of code. In this scenario, it calls rcureadunlockspecial(), which uses an irq-work handler to force the system to notice when the RCU read-side critical section ends. The issue specifically affects the per-CPU rcudata structure's ->deferqsiwpending field, which is updated by both the irq-work handler and rcureadunlockspecial(), leading to a data race condition. This race condition was detected by KCSAN (Kernel Concurrency Sanitizer) (NVD).

Impact

The vulnerability affects Linux kernel systems using the RCU subsystem with specific configurations. The issue is particularly relevant for kernels booted with rcutree.use_softirq=y, where the irq-work handler is used unconditionally (NVD).

Mitigation and workarounds

The issue has been resolved by disabling interrupts across the portion of the rcupreemptdeferredqshandler() that updates the ->deferqsiw_pending field. This solution was deemed appropriate as this handler is not on a critical performance path (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40343MEDIUM6.4
  • Linux KernelLinux Kernel
  • kernel-rt-modules-internal
NoYesDec 09, 2025
CVE-2025-40342MEDIUM6.4
  • Linux KernelLinux Kernel
  • kernel-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40341MEDIUM5.1
  • Linux KernelLinux Kernel
  • linux-nvidia-tegra
NoYesDec 09, 2025
CVE-2025-40345N/AN/A
  • Linux KernelLinux Kernel
  • kernel-headers
NoYesDec 12, 2025
CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management