CVE-2025-39752
In the Linux kernel, the following vulnerability has been resolved: ARM: rockchip: fix kernel hang during smp initialization In order to bring up secondary CPUs main CPU write trampoline code to SRAM.
Does this matter?
Lower severity and a low EPSS score (0.17%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: ARM: rockchip: fix kernel hang during smp initialization In order to bring up secondary CPUs main CPU write trampoline code to SRAM. The trampoline code is written while secondary CPUs are powered on (at least that true for RK3188 CPU). Sometimes that leads to kernel hang. Probably because secondary CPU execute trampoline code while kernel doesn't expect. The patch moves SRAM initialization step to the point where all secondary CPUs are powered down. That fixes rarely hangs on RK3188: [ 0.091568] CPU0: thread -1, cpu 0, socket 0, mpidr 80000000 [ 0.091996] rockchip_smp_prepare_cpus: ncores 4
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.17% probability · 7th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel · debian/debian linux
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/0223a3683d502b7e5eb2eb4ad7e97363fa88d531Patch
- https://git.kernel.org/stable/c/1eb67589a7e091b1e5108aab72fddbf4dc69af2cPatch
- https://git.kernel.org/stable/c/265583266d93db4ff83d088819b1f63fdf0131dbPatch
- https://git.kernel.org/stable/c/3c6bf7a324b8995b9c7d790c8d2abf0668f51551Patch
- https://git.kernel.org/stable/c/47769dab9073a73e127aa0bfd0ba4c51eaccdc33Patch
- https://git.kernel.org/stable/c/7cdb433bb44cdc87dc5260cdf15bf03cc1cd1814Patch
- https://git.kernel.org/stable/c/888a453c2a239765a7ab4de8a3cedae2e3802528Patch
- https://git.kernel.org/stable/c/c0726d1e466e2d0da620836e293a59e6427ccdffPatch
- https://git.kernel.org/stable/c/d7d6d076ee9532c4668f14696a35688d35dd16f4Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.htmlMailing List, Third Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.