目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-39773— Linux kernel 安全漏洞

AI Predicted 5.3 Difficulty: Trivial EPSS 0.11% · P2

Affected Version Matrix 14

ベンダープロダクトVersion Rangeステータス
LinuxLinuxd902eee43f1951b358d7347d9165c6af21cf7b1b< 34171b9e53bd1dc264f5556579f2b04f04435c73affected
d902eee43f1951b358d7347d9165c6af21cf7b1b< 43e281fde5e76a866a4d10780c35023f16c0e432affected
d902eee43f1951b358d7347d9165c6af21cf7b1b< 96476b043efb86a94f2badd260f7f99c97bd5893affected
d902eee43f1951b358d7347d9165c6af21cf7b1b< bdb19cd0de739870bb3494c815138b9dc30875c4affected
d902eee43f1951b358d7347d9165c6af21cf7b1b< 5bf5fce8a0c2a70d063af778fdb5b27238174cddaffected
d902eee43f1951b358d7347d9165c6af21cf7b1b< d1547bf460baec718b3398365f8de33d25c5f36faffected
2.6.34affected
< 2.6.34unaffected
… +6 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-39773の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
net: bridge: fix soft lockup in br_multicast_query_expired()
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: net: bridge: fix soft lockup in br_multicast_query_expired() When set multicast_query_interval to a large value, the local variable 'time' in br_multicast_send_query() may overflow. If the time is smaller than jiffies, the timer will expire immediately, and then call mod_timer() again, which creates a loop and may trigger the following soft lockup issue. watchdog: BUG: soft lockup - CPU#1 stuck for 221s! [rb_consumer:66] CPU: 1 UID: 0 PID: 66 Comm: rb_consumer Not tainted 6.16.0+ #259 PREEMPT(none) Call Trace: <IRQ> __netdev_alloc_skb+0x2e/0x3a0 br_ip6_multicast_alloc_query+0x212/0x1b70 __br_multicast_send_query+0x376/0xac0 br_multicast_send_query+0x299/0x510 br_multicast_query_expired.constprop.0+0x16d/0x1b0 call_timer_fn+0x3b/0x2a0 __run_timers+0x619/0x950 run_timer_softirq+0x11c/0x220 handle_softirqs+0x18e/0x560 __irq_exit_rcu+0x158/0x1a0 sysvec_apic_timer_interrupt+0x76/0x90 </IRQ> This issue can be reproduced with: ip link add br0 type bridge echo 1 > /sys/class/net/br0/bridge/multicast_querier echo 0xffffffffffffffff > /sys/class/net/br0/bridge/multicast_query_interval ip link set dev br0 up The multicast_startup_query_interval can also cause this issue. Similar to the commit 99b40610956a ("net: bridge: mcast: add and enforce query interval minimum"), add check for the query interval maximum to fix this issue.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于br_multicast_query_expired函数中multicast_query_interval设置过大导致时间溢出,可能触发软锁定问题。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux d902eee43f1951b358d7347d9165c6af21cf7b1b ~ 34171b9e53bd1dc264f5556579f2b04f04435c73 -
LinuxLinux 2.6.34 -

II. CVE-2025-39773の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-39773のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-09-11 · 54 CVEs total

CVE-2025-397589.8 CRITICALRDMA/siw: Fix the sendmsg byte count in siw_tcp_sendpages
CVE-2025-397618.8 HIGHwifi: ath12k: Decrement TID on RX peer frag setup error handling
CVE-2025-397508.8 HIGHwifi: ath12k: Correct tid cleanup when tid setup fails
CVE-2025-397908.4 HIGHbus: mhi: host: Detect events pointing to unexpected TREs
CVE-2025-397797.8 HIGHbtrfs: subpage: keep TOWRITE tag until folio is cleaned
CVE-2025-397857.8 HIGHdrm/hisilicon/hibmc: fix irq_request()'s irq name variable is local
CVE-2025-397867.8 HIGHiio: adc: ad7173: fix channels index for syscalib_mode
CVE-2025-397877.8 HIGHsoc: qcom: mdt_loader: Ensure we don't read past the ELF header
CVE-2025-397407.8 HIGHdrm/xe/migrate: prevent potential UAF
CVE-2025-397807.8 HIGHsched/ext: Fix invalid task state transitions on class switch
CVE-2025-397917.8 HIGHdm: dm-crypt: Do not partially accept write BIOs with zoned targets
CVE-2025-397707.5 HIGHnet: gso: Forbid IPv6 TSO with extensions on devices with only IPV6_CSUM
CVE-2025-397387.3 HIGHbtrfs: do not allow relocation of partially dropped subvolumes
CVE-2025-397897.3 HIGHcrypto: x86/aegis - Add missing error checks
CVE-2025-397767.0 HIGHmm/debug_vm_pgtable: clear page table entries at destroy_args()
CVE-2025-39769bnxt_en: Fix lockdep warning during rmmod
CVE-2025-39771regulator: pca9450: Use devm_register_sys_off_handler
CVE-2025-39782jbd2: prevent softlockup in jbd2_log_do_checkpoint()
CVE-2025-39784PCI: Fix link speed calculation on retrain failure
CVE-2025-39783PCI: endpoint: Fix configfs group list head handling

Showing 20 of 54 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2025-39773へのコメント

まだコメントはありません


コメントを残す