CVE-2025-38717: net: kcm: Fix race condition in kcm_unattach()

Published Sep 4, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

net: kcm: Fix race condition in kcmunattach()

syzbot found a race condition when kcmunattach(psock) and kcmrelease(kcm) are executed at the same time.

kcmunattach() is missing a check of the flag kcm->txstopped before calling queuework().

If the kcm has a reserved psock, kcmunattach() might get executed between cancelworksync() and unreservepsock() in kcmrelease(), requeuing kcm->txwork right before kcm gets freed in kcmdone().

Remove kcm->txstopped and replace it by the less error-prone disableworksync().

Affected Software

12 affected components
Linux Kernel
Microsoft azl3 kernel 6.6.96.2-1
Microsoft azl3 kernel 6.6.96.2-2
Linux Linux kernel>=4.6<6.12.43
Linux Linux kernel>=6.13<6.15.11
Linux Linux kernel>=6.16<6.16.2
Linux Linux kernel=6.17-rc1
Microsoft cbl2 kernel 5.15.186.1-1
Microsoft azl3 kernel 6.6.104.2-4
Microsoft azl3 kernel 6.6.112.1-2
Microsoft azl3 kernel 6.6.117.1-1
Microsoft azl3 kernel 6.6.119.3-1

Event History

Sep 4, 2025
CVE Published
via MITRE·03:33 PM
Data Sourced
via MITRE·03:33 PM
DescriptionSeverity
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Sep 6, 2025
Data Sourced
via Microsoft·01:12 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·01:12 AM
Affected Software
Updated
via Microsoft·01:12 AM
SeverityAffected Software
Updated
via Microsoft·08:12 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-38717?

CVE-2025-38717 has been classified with a medium severity due to the potential for a race condition in the Linux kernel.

2

How do I fix CVE-2025-38717?

You can address CVE-2025-38717 by updating your Linux kernel to the latest version where the vulnerability has been patched.

3

What components are affected by CVE-2025-38717?

CVE-2025-38717 affects the Linux kernel, specifically components related to the kcm module.

4

What is a race condition in the context of CVE-2025-38717?

In the context of CVE-2025-38717, a race condition occurs when kcm_unattach() and kcm_release(kcm) are executed simultaneously without proper locking mechanisms.

5

Who discovered CVE-2025-38717?

CVE-2025-38717 was reported by the syzbot automated testing tool which identified the race condition.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203