CVE-2025-38717: net: kcm: Fix race condition in kcm_unattach()
In the Linux kernel, the following vulnerability has been resolved:
net: kcm: Fix race condition in kcmunattach()
syzbot found a race condition when kcmunattach(psock) and kcmrelease(kcm) are executed at the same time.
kcmunattach() is missing a check of the flag kcm->txstopped before calling queuework().
If the kcm has a reserved psock, kcmunattach() might get executed between cancelworksync() and unreservepsock() in kcmrelease(), requeuing kcm->txwork right before kcm gets freed in kcmdone().
Remove kcm->txstopped and replace it by the less error-prone disableworksync().
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-38717?
CVE-2025-38717 has been classified with a medium severity due to the potential for a race condition in the Linux kernel.
How do I fix CVE-2025-38717?
You can address CVE-2025-38717 by updating your Linux kernel to the latest version where the vulnerability has been patched.
What components are affected by CVE-2025-38717?
CVE-2025-38717 affects the Linux kernel, specifically components related to the kcm module.
What is a race condition in the context of CVE-2025-38717?
In the context of CVE-2025-38717, a race condition occurs when kcm_unattach() and kcm_release(kcm) are executed simultaneously without proper locking mechanisms.
Who discovered CVE-2025-38717?
CVE-2025-38717 was reported by the syzbot automated testing tool which identified the race condition.