# CVE-2025-39681

## Summary

- **CVE ID:** CVE-2025-39681
- **Severity:** MEDIUM
- **CVSS Score:** 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** N/A
- **Published:** Sep 5, 2025
- **Last Modified:** Sep 8, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

x86/cpu/hygon: Add missing resctrl_cpu_detect() in bsp_init helper

Since

  923f3a2b48bd ("x86/resctrl: Query LLC monitoring properties once during boot")

resctrl_cpu_detect() has been moved from common CPU initialization code to
the vendor-specific BSP init helper, while Hygon didn't put that call in their
code.

This triggers a division by zero fault during early booting stage on our
machines with X86_FEATURE_CQM* supported, where get_rdt_mon_resources() tries
to calculate mon_l3_config with uninitialized boot_cpu_data.x86_cache_occ_scale.

Add the missing resctrl_cpu_detect() in the Hygon BSP init helper.

  [ bp: Massage commit message. ]

## Affected Products

- Linux — Linux (923f3a2b48bdccb6a1d1f0dd48de03de7ad936d9)
- Linux — Linux (5.8)
- Linux — Linux (0)
- Linux — Linux (5.10.242)
- Linux — Linux (5.15.190)
- Linux — Linux (6.1.149)
- Linux — Linux (6.6.103)
- Linux — Linux (6.12.44)
- Linux — Linux (6.16.4)
- Linux — Linux (6.17)

## References

- [CNA](https://git.kernel.org/stable/c/62f12cde10118253348a7540e85606869bd69432)
- [CNA](https://git.kernel.org/stable/c/873f32201df8876bdb2563e3187e79149427cab4)
- [CNA](https://git.kernel.org/stable/c/fb81222c1559f89bfe3aa1010f6d112531d55353)
- [CNA](https://git.kernel.org/stable/c/7207923d8453ebfb35667c1736169f2dd796772e)
- [CNA](https://git.kernel.org/stable/c/a9e5924daa954c9f585c1ca00358afe71d6781c4)
- [CNA](https://git.kernel.org/stable/c/d23264c257a70dbe021b43b3bc2ee16134cd2c69)
- [CNA](https://git.kernel.org/stable/c/d8df126349dad855cdfedd6bbf315bad2e901c2f)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-032379.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-019113.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 6.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._