CVE-2025-39737Disclosure(debian / debian_linux)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: mm/kmemleak: avoid soft lockup in __kmemleak_do_cleanup() A soft lockup warning was observed on a relative small system x86-64 system with 16 GB of memory when running a debug kernel with kmemleak enabled. watchdog: BUG: soft lockup - CPU#8 stuck for 33s! [kworker/8:1:134] The test system was running a workload with hot unplug happening in parallel. Then kemleak decided to disable itself due to its inability to allocate more kmemleak objects. The debug kernel has its CONFIG_DEBUG_KMEMLEAK_MEM_POOL_SIZE set to 40,000. The soft lockup happened in kmemleak_do_cleanup() when the existing kmemleak objects were being removed and deleted one-by-one in a loop via a workqueue. In this particular case, there are at least 40,000 objects that need to be processed and given the slowness of a debug kernel and the fact that a raw_spinlock has to be acquired and released in __delete_object(), it could take a while to properly handle all these objects. As kmemleak has been disabled in this case, the object removal and deletion process can be further optimized as locking isn't really needed. However, it is probably not worth the effort to optimize for such an edge case that should rarely happen. So the simple solution is to call cond_resched() at periodic interval in the iteration loop to avoid soft lockup.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-401

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • linux_kernel

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
debian_linuxlinux_kernel

3 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-11: 1Technical Details · 2026-07-11: 107-11
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • BREACHSPIDER@breachspider
    Disclosure

    [CVE Analysis] CVE-2025-39737: SIMATIC CN 4100 Multiple Memory Corruption Flaws Below Version 5.0 https://breachspider.com/intel/2026-07-11-cve-2025-39737-simatic-cn-4100-multiple-memory-corruption-fl #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    The post announces CVE-2025-39737, noting multiple memory corruption flaws in SIMATIC CN 4100 models below version 5.0, and links to an analysis page without providing PoC, exploit code, patches, or evidence of active exploitation.

    0000041
    2.3K followersView on X
CPE platform detail9 entries

9 of 9 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
OSlinuxlinux_kernel---
OSlinuxlinux_kernel5.4--
OSlinuxlinux_kernel5.4--
OSlinuxlinux_kernel5.4--
OSlinuxlinux_kernel5.4--
OSlinuxlinux_kernel5.4--
OSlinuxlinux_kernel5.4--
OSlinuxlinux_kernel6.17--

Explore more