CVE-2025-38008

MEDIUM EPSS 1.6%
Published Jun 18, 20251y ago · Modified Jun 17, 20262w ago
4.7 CVSS 3.1
Medium
Find Similar
Published Jun 18, 2025 1y ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix race condition in unaccepted memory handling The page allocator tracks the number of zones that have unaccepted memory using static_branch_enc/dec() and uses that static branch in hot paths to determine if it needs to deal with unaccepted memory. Borislav and Thomas pointed out that the tracking is racy: operations on static_branch are not serialized against adding/removing unaccepted pages to/from the zone. Sanity checks inside static_branch machinery detects it: WARNING: CPU: 0 PID: 10 at kernel/jump_label.c:276 __static_key_slow_dec_cpuslocked+0x8e/0xa0 The comment around the WARN() explains the problem: /* * Warn about the '-1' case though; since that means a * decrement is concurrent with a first (0->1) increment. IOW * people are trying to disable something that wasn't yet fully * enabled. This suggests an ordering problem on the user side. */ The effect of this static_branch optimization is only visible on microbenchmark. Instead of adding more complexity around it, remove it altogether.

CVSS Details

Base Score
4.7
Exploitability
1.0
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
1.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-362

Affected Products 9

VendorProductVersionRange
linuxlinux_kernel*≥6.5  –  <6.6.92
linuxlinux_kernel*≥6.7  –  <6.12.30
linuxlinux_kernel*≥6.13  –  <6.14.8
linuxlinux_kernel6.15any
linuxlinux_kernel6.15any
linuxlinux_kernel6.15any
linuxlinux_kernel6.15any
linuxlinux_kernel6.15any
linuxlinux_kernel6.15any

References 4

  • git.kernel.org https://git.kernel.org/stable/c/71dda1cb10702dc2859f00eb789b0502de2176a9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/74953f93f47a45296cc2a3fd04e2a3202ff3fa53
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/98fdd2f612e949c652693f6df00442c81037776d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fefc075182275057ce607effaa3daa9e6e3bdc73
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/71dda1cb10702dc2859f00eb789b0502de2176a9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/74953f93f47a45296cc2a3fd04e2a3202ff3fa53
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/98fdd2f612e949c652693f6df00442c81037776d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fefc075182275057ce607effaa3daa9e6e3bdc73
    Patch