CVE-2025-38369

HIGH EPSS 5.0%
Published Jul 25, 202511mo ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published Jul 25, 2025 11mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Check availability of workqueue allocated by idxd wq driver before using Running IDXD workloads in a container with the /dev directory mounted can trigger a call trace or even a kernel panic when the parent process of the container is terminated. This issue occurs because, under certain configurations, Docker does not properly propagate the mount replica back to the original mount point. In this case, when the user driver detaches, the WQ is destroyed but it still calls destroy_workqueue() attempting to completes all pending work. It's necessary to check wq->wq and skip the drain if it no longer exists.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
5.0% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-416 Use After Free Memory Safety

Affected Products 3

VendorProductVersionRange
linuxlinux_kernel*≥5.6  –  <6.6.96
linuxlinux_kernel*≥6.7  –  <6.12.36
linuxlinux_kernel*≥6.13  –  <6.15.5

References 4

  • git.kernel.org https://git.kernel.org/stable/c/17502e7d7b7113346296f6758324798d536c31fd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/98fd66c8ba77e3a7137575f610271014bc0e701f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/aee7a7439f8c0884da87694a401930204a57128f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e0051a3daa8b2cb318b03b2f9317c3e40855847a
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/17502e7d7b7113346296f6758324798d536c31fd
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/98fd66c8ba77e3a7137575f610271014bc0e701f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/aee7a7439f8c0884da87694a401930204a57128f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e0051a3daa8b2cb318b03b2f9317c3e40855847a
    Patch