CVE-2025-40348
NONE EPSS 6.2%
Published Dec 16, 20256mo ago · Modified Jun 17, 20262w ago
Published Dec 16, 2025 6mo ago
Last Modified Jun 17, 2026 2w ago
Description
In the Linux kernel, the following vulnerability has been resolved: slab: Avoid race on slab->obj_exts in alloc_slab_obj_exts If two competing threads enter alloc_slab_obj_exts() and one of them fails to allocate the object extension vector, it might override the valid slab->obj_exts allocated by the other thread with OBJEXTS_ALLOC_FAIL. This will cause the thread that lost this race and expects a valid pointer to dereference a NULL pointer later on. Update slab->obj_exts atomically using cmpxchg() to avoid slab->obj_exts overrides by racing threads. Thanks for Vlastimil and Suren's help with debugging.
Threat Intelligence
EPSS Exploit Probability
6.2% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
References 3
- git.kernel.org https://git.kernel.org/stable/c/6ed8bfd24ce1cb31742b09a3eb557cd008533eec
- git.kernel.org https://git.kernel.org/stable/c/7c34feda6a9a203c9744281f1b6671b7dad2012d
- git.kernel.org https://git.kernel.org/stable/c/c7af5300d78460fc5037ddc77113ba3dbfe77dc0
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.