In the Linux kernel, the following vulnerability has been resolved:
mm/kmemleak: avoid soft lockup in _kmemleakdo_cleanup()
A soft lockup warning was observed on a relative small system x86-64 system with 16 GB of memory when running a debug kernel with kmemleak enabled.
watchdog: BUG: soft lockup - CPU#8 stuck for 33s! [kworker/8:1:134]
The test system was running a workload with hot unplug happening in parallel. Then kemleak decided to disable itself due to its inability to allocate more kmemleak objects. The debug kernel has its CONFIGDEBUGKMEMLEAKMEMPOOL_SIZE set to 40,000.
The soft lockup happened in kmemleakdocleanup() when the existing kmemleak objects were being removed and deleted one-by-one in a loop via a workqueue. In this particular case, there are at least 40,000 objects that need to be processed and given the slowness of a debug kernel and the fact that a rawspinlock has to be acquired and released in _delete_object(), it could take a while to properly handle all these objects.
As kmemleak has been disabled in this case, the object removal and deletion process can be further optimized as locking isn't really needed. However, it is probably not worth the effort to optimize for such an edge case that should rarely happen. So the simple solution is to call cond_resched() at periodic interval in the iteration loop to avoid soft lockup.
[
    {
        "signature_type": "Line",
        "target": {
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1ef72a7fedc5bca70e8cc980985790de10d407aa",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "280598543976857232706724621794165882646",
                "89990367296322302945014709656543647089",
                "146600854860485079630889715928976333177",
                "154375573673946243110708725219825388728",
                "249639452072060663589514632270556235349",
                "65970245775331686395590275899300302881",
                "55284501813968436941728009302988267302"
            ]
        },
        "id": "CVE-2025-39737-0470c863",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "target": {
            "function": "__kmemleak_do_cleanup",
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e21a3ddd58733ce31afcb1e5dc3cb80a4b5bc29b",
        "digest": {
            "function_hash": "301965032532771442501367040654716592237",
            "length": 168.0
        },
        "id": "CVE-2025-39737-549cdd3a",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "target": {
            "function": "__kmemleak_do_cleanup",
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@926092268efdf1ed7b55cf486356c74a9e7710d1",
        "digest": {
            "function_hash": "301965032532771442501367040654716592237",
            "length": 168.0
        },
        "id": "CVE-2025-39737-644da95d",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d1534ae23c2b6be350c8ab060803fbf6e9682adc",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "280598543976857232706724621794165882646",
                "89990367296322302945014709656543647089",
                "146600854860485079630889715928976333177",
                "154375573673946243110708725219825388728",
                "249639452072060663589514632270556235349",
                "65970245775331686395590275899300302881",
                "55284501813968436941728009302988267302"
            ]
        },
        "id": "CVE-2025-39737-71edc0c9",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f014c10d190b92aad366e56b445daffcd1c075e4",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "280598543976857232706724621794165882646",
                "89990367296322302945014709656543647089",
                "146600854860485079630889715928976333177",
                "154375573673946243110708725219825388728",
                "249639452072060663589514632270556235349",
                "65970245775331686395590275899300302881",
                "55284501813968436941728009302988267302"
            ]
        },
        "id": "CVE-2025-39737-795410eb",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "target": {
            "function": "__kmemleak_do_cleanup",
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f014c10d190b92aad366e56b445daffcd1c075e4",
        "digest": {
            "function_hash": "301965032532771442501367040654716592237",
            "length": 168.0
        },
        "id": "CVE-2025-39737-8577c1ab",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "target": {
            "function": "__kmemleak_do_cleanup",
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@1ef72a7fedc5bca70e8cc980985790de10d407aa",
        "digest": {
            "function_hash": "301965032532771442501367040654716592237",
            "length": 168.0
        },
        "id": "CVE-2025-39737-94e1e70d",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e21a3ddd58733ce31afcb1e5dc3cb80a4b5bc29b",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "280598543976857232706724621794165882646",
                "89990367296322302945014709656543647089",
                "146600854860485079630889715928976333177",
                "154375573673946243110708725219825388728",
                "249639452072060663589514632270556235349",
                "65970245775331686395590275899300302881",
                "55284501813968436941728009302988267302"
            ]
        },
        "id": "CVE-2025-39737-9ce39293",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a04de4c40aab9b338dfa989cf4aec70fd187eeb2",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "280598543976857232706724621794165882646",
                "89990367296322302945014709656543647089",
                "146600854860485079630889715928976333177",
                "154375573673946243110708725219825388728",
                "249639452072060663589514632270556235349",
                "65970245775331686395590275899300302881",
                "55284501813968436941728009302988267302"
            ]
        },
        "id": "CVE-2025-39737-a9c5bf4f",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9f1f4e95031f84867c5821540466d62f88dab8ca",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "280598543976857232706724621794165882646",
                "89990367296322302945014709656543647089",
                "146600854860485079630889715928976333177",
                "154375573673946243110708725219825388728",
                "249639452072060663589514632270556235349",
                "65970245775331686395590275899300302881",
                "55284501813968436941728009302988267302"
            ]
        },
        "id": "CVE-2025-39737-baf15e76",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "target": {
            "function": "__kmemleak_do_cleanup",
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a04de4c40aab9b338dfa989cf4aec70fd187eeb2",
        "digest": {
            "function_hash": "301965032532771442501367040654716592237",
            "length": 168.0
        },
        "id": "CVE-2025-39737-bf196af9",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "target": {
            "function": "__kmemleak_do_cleanup",
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9f1f4e95031f84867c5821540466d62f88dab8ca",
        "digest": {
            "function_hash": "301965032532771442501367040654716592237",
            "length": 168.0
        },
        "id": "CVE-2025-39737-c65bc18b",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@926092268efdf1ed7b55cf486356c74a9e7710d1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "280598543976857232706724621794165882646",
                "89990367296322302945014709656543647089",
                "146600854860485079630889715928976333177",
                "154375573673946243110708725219825388728",
                "249639452072060663589514632270556235349",
                "65970245775331686395590275899300302881",
                "55284501813968436941728009302988267302"
            ]
        },
        "id": "CVE-2025-39737-e018b024",
        "signature_version": "v1"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8d2d22a55ffe35c38e69795468a7addd1a80e9ce",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "280598543976857232706724621794165882646",
                "89990367296322302945014709656543647089",
                "146600854860485079630889715928976333177",
                "154375573673946243110708725219825388728",
                "249639452072060663589514632270556235349",
                "65970245775331686395590275899300302881",
                "55284501813968436941728009302988267302"
            ]
        },
        "id": "CVE-2025-39737-f043e1a6",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "target": {
            "function": "__kmemleak_do_cleanup",
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d1534ae23c2b6be350c8ab060803fbf6e9682adc",
        "digest": {
            "function_hash": "301965032532771442501367040654716592237",
            "length": 168.0
        },
        "id": "CVE-2025-39737-f64a9461",
        "signature_version": "v1"
    },
    {
        "signature_type": "Function",
        "target": {
            "function": "__kmemleak_do_cleanup",
            "file": "mm/kmemleak.c"
        },
        "deprecated": false,
        "source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8d2d22a55ffe35c38e69795468a7addd1a80e9ce",
        "digest": {
            "function_hash": "301965032532771442501367040654716592237",
            "length": 168.0
        },
        "id": "CVE-2025-39737-fa25aab7",
        "signature_version": "v1"
    }
]