Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: x86/cpu/hygon: Add missing resctrl_cpu_detect() in bsp_init helper Since 923f3a2b48bd ("x86/resctrl: Query LLC monitoring properties once during boot") resctrl_cpu_detect() has been moved from common CPU initialization code to the vendor-specific BSP init helper, while Hygon didn't put that call in their code. This triggers a division by zero fault during early booting stage on our machines with X86_FEATURE_CQM* supported, where get_rdt_mon_resources() tries to calculate mon_l3_config with uninitialized boot_cpu_data.x86_cache_occ_scale. Add the missing resctrl_cpu_detect() in the Hygon BSP init helper. [ bp: Massage commit message. ]
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 5.8, < 5.10.242 |
| Debian | Debian Linux | 11.0 |
References
- https://git.kernel.org/stable/c/62f12cde10118253348a7540e85606869bd69432Patch
- https://git.kernel.org/stable/c/7207923d8453ebfb35667c1736169f2dd796772ePatch
- https://git.kernel.org/stable/c/873f32201df8876bdb2563e3187e79149427cab4Patch
- https://git.kernel.org/stable/c/a9e5924daa954c9f585c1ca00358afe71d6781c4Patch
- https://git.kernel.org/stable/c/d23264c257a70dbe021b43b3bc2ee16134cd2c69Patch
- https://git.kernel.org/stable/c/d8df126349dad855cdfedd6bbf315bad2e901c2fPatch
- https://git.kernel.org/stable/c/fb81222c1559f89bfe3aa1010f6d112531d55353Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00007.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.htmlThird Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html
FAQ
What is CVE-2025-39681?
CVE-2025-39681 is a vulnerability with a CVSS score of 5.5 (MEDIUM). In the Linux kernel, the following vulnerability has been resolved: x86/cpu/hygon: Add missing resctrl_cpu_detect() in bsp_init helper Since 923f3a2b48bd ("x86/resctrl: Query LLC monitoring prope...
How severe is CVE-2025-39681?
CVE-2025-39681 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-39681?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux.