System interruption via uninitialized kexec buffer field
Published Oct 1, 2025 · Updated May 11, 2026
Use of uninitialized data in Linux kernel 6.16 through 6.16.7 allows local users to interrupt arm64 systems through kexec file loading. The arm64 load_other_segments() path leaves kexec_buf partly uninitialized, then kexec_add_buffer() reads its garbage random Boolean and triggers an invalid load. Reachability requires local access to the arm64 kexec file-loading path; the published impact is limited to system availability.
Summary
What happened
Use of uninitialized data in Linux kernel 6.16 through 6.16.7 allows local users to interrupt arm64 systems through kexec file loading. The arm64 load_other_segments() path leaves kexec_buf partly uninitialized, then kexec_add_buffer() reads its garbage random Boolean and triggers an invalid load. Reachability requires local access to the arm64 kexec file-loading path; the published impact is limited to system availability.
The record
- CVE
- CVE-2025-39904
- Published
- Oct 1, 2025
- Updated
- May 11, 2026
- Vendor
- The Linux Kernel Organization
- Product
- Linux
- Classifications
- CWE-908, T1499.004
- Attack vector
- local
- Privileges
- authenticated
Timeline
How it unfolded
- Oct 1, 2025CVE publishedPublication date reported by the CVE source.
- May 11, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=6.16
- Affected versionversion=bf454ec31add6790f6cdc88328e38901fcbbade6 <04d3cd43700a2d0fe4bfb1012a8ec7f2e34a3507
- Affected versionversion=bf454ec31add6790f6cdc88328e38901fcbbade6 <340cc9a3bd30b25edaf6a9708d41b5f2c10a054a
What conditions does exploitation require?
What is affected?
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo