cbcvebase.
CVE-2025-23138
published 2025-04-16

CVE-2025-23138: In the Linux kernel, the following vulnerability has been resolved: watch_queue: fix pipe accounting mismatch Currently, watch_queue_set_size() modifies the…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved: watch_queue: fix pipe accounting mismatch Currently, watch_queue_set_size() modifies the pipe buffers charged to user->pipe_bufs without updating the pipe->nr_accounted on the pipe itself, due to the if (!pipe_has_watch_queue()) test in pipe_resize_ring(). This means that when the pipe is ultimately freed, we decrement user->pipe_bufs by something other than what than we had charged to it, potentially leading to an underflow. This in turn can cause subsequent too_many_pipe_buffers_soft() tests to fail with -EPERM. To remedy this, explicitly account for the pipe usage in watch_queue_set_size() to match the number set via account_pipe_buffers() (It's unclear why watch_queue_set_size() does not update nr_accounted; it may be due to intentional overprovisioning in watch_queue_set_size()?)

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 162ae0e78bdabf84ef10c1293c4ed7865cb7d3c8 < 8658c75343ed00e5e154ebbe24335f51ba8db5478658c75343ed00e5e154ebbe24335f51ba8db547
linuxlinux>= 3efbd114b91525bb095b8ae046382197d92126b9 < 471c89b7d4f58bd6082f7c1fe14d4ca15c7f1284471c89b7d4f58bd6082f7c1fe14d4ca15c7f1284
linuxlinux>= 5.10.210 < 5.10.2365.10.236
linuxlinux>= 5.15.149 < 5.15.1805.15.180
linuxlinux>= 6.1.76 < 6.1.1346.1.134
linuxlinux>= 6.6.15 < 6.6.876.6.87
linuxlinux>= 6.7.3 < 6.86.8
linuxlinux>= 68e51bdb1194f11d3452525b99c98aff6f837b24 < 6dafa27764183738dc5368b669b71e3d0d154f126dafa27764183738dc5368b669b71e3d0d154f12
linuxlinux>= b87a1229d8668fbc78ebd9ca0fc797a76001c60f < d40e3537265dea9e3c33021874437ff26dc18787d40e3537265dea9e3c33021874437ff26dc18787
linuxlinux>= e95aada4cb93d42e25c30a0ef9eb2923d9711d4a < 56ec918e6c86c1536870e4373e91eddd0c44245f56ec918e6c86c1536870e4373e91eddd0c44245f
linuxlinux>= e95aada4cb93d42e25c30a0ef9eb2923d9711d4a < 2d680b988656bb556c863d8b46d9b9096842bf3d2d680b988656bb556c863d8b46d9b9096842bf3d
linuxlinux>= e95aada4cb93d42e25c30a0ef9eb2923d9711d4a < 205028ebba838938d3b264dda1d0708fa7fe1ade205028ebba838938d3b264dda1d0708fa7fe1ade
linuxlinux>= e95aada4cb93d42e25c30a0ef9eb2923d9711d4a < f13abc1e8e1a3b7455511c4e122750127f6bc9b0f13abc1e8e1a3b7455511c4e122750127f6bc9b0
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-86.876.8.0-86.87
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.