PT-2025-36298 · Linux+1 · Linux Kernel+1

Published

2025-08-20

·

Updated

2025-09-06

·

CVE-2025-39704

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.17.0-rc1+ #102
Description A stack buffer overflow issue exists in the send ipi data() function within the Linux kernel, specifically related to the LoongArch architecture and KVM functionality. The kvm io bus read() function, called by send ipi data(), does not adequately validate the size of the buffer pointed to by the val parameter, potentially leading to a buffer overflow when CONFIG STACKPROTECTOR is enabled. This can result in a kernel panic, as demonstrated by the provided stack trace.
Recommendations Update to a version of the Linux kernel newer than 6.17.0-rc1+ #102.

Exploit

Fix

Uncontrolled Recursion

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-03099
CVE-2025-39704

Affected Products

Astra Linux
Linux Kernel