cbcvebase.
CVE-2025-38008
published 2025-06-18

CVE-2025-38008: In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix race condition in unaccepted memory handling The page allocator tracks…

PriorityP416medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.11%
1.7th percentile
In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix race condition in unaccepted memory handling The page allocator tracks the number of zones that have unaccepted memory using static_branch_enc/dec() and uses that static branch in hot paths to determine if it needs to deal with unaccepted memory. Borislav and Thomas pointed out that the tracking is racy: operations on static_branch are not serialized against adding/removing unaccepted pages to/from the zone. Sanity checks inside static_branch machinery detects it: WARNING: CPU: 0 PID: 10 at kernel/jump_label.c:276 __static_key_slow_dec_cpuslocked+0x8e/0xa0 The comment around the WARN() explains the problem: /* * Warn about the '-1' case though; since that means a * decrement is concurrent with a first (0->1) increment. IOW * people are trying to disable something that wasn't yet fully * enabled. This suggests an ordering problem on the user side. */ The effect of this static_branch optimization is only visible on microbenchmark. Instead of adding more complexity around it, remove it altogether.

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.30-1 (forky)linux 6.12.30-1 (forky)
linuxlinux
linuxlinux>= dcdfdd40fa82b6704d2841938e5c8ec3051eb0d6 < 98fdd2f612e949c652693f6df00442c81037776d98fdd2f612e949c652693f6df00442c81037776d
linuxlinux>= dcdfdd40fa82b6704d2841938e5c8ec3051eb0d6 < 74953f93f47a45296cc2a3fd04e2a3202ff3fa5374953f93f47a45296cc2a3fd04e2a3202ff3fa53
linuxlinux>= dcdfdd40fa82b6704d2841938e5c8ec3051eb0d6 < 71dda1cb10702dc2859f00eb789b0502de2176a971dda1cb10702dc2859f00eb789b0502de2176a9
linuxlinux>= dcdfdd40fa82b6704d2841938e5c8ec3051eb0d6 < fefc075182275057ce607effaa3daa9e6e3bdc73fefc075182275057ce607effaa3daa9e6e3bdc73
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.30-16.12.30-1
linuxlinux_kernel>= 0 < 6.12.30-16.12.30-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 6.13 < 6.14.86.14.8
linuxlinux_kernel>= 6.5 < 6.6.926.6.92
linuxlinux_kernel>= 6.7 < 6.12.306.12.30
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-oracle
ubuntulinux-oracle-6.8
ubuntulinux-raspi-realtime
ubuntulinux-realtime

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.