CVE-2025-38028Race Condition in Linux

Severity
4.7MEDIUMNVD
OSV7.8
EPSS
0.0%
top 87.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 18
Latest updateAug 28

Description

In the Linux kernel, the following vulnerability has been resolved: NFS/localio: Fix a race in nfs_local_open_fh() Once the clp->cl_uuid.lock has been dropped, another CPU could come in and free the struct nfsd_file that was just added. To prevent that from happening, take the RCU read lock before dropping the spin lock.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages3 packages

NVDlinux/linux_kernel6.146.14.8+1
CVEListV5linux/linux86e00412254a717ffd5d38dc5ec0ee1cce6281b3185a2f2ddabdcf999823f61de67f86376883920d+2
debiandebian/linux

Patches

🔴Vulnerability Details

5
OSV
linux-azure vulnerabilities2025-08-28
OSV
linux-hwe-6.14, linux-oem-6.14 vulnerabilities2025-08-20
OSV
linux, linux-aws, linux-aws-6.14, linux-gcp, linux-gcp-6.14, linux-oracle, linux-oracle-6.14, linux-raspi, linux-realtime vulnerabilities2025-08-18
OSV
CVE-2025-38028: In the Linux kernel, the following vulnerability has been resolved: NFS/localio: Fix a race in nfs_local_open_fh() Once the clp->cl_uuid2025-06-18
GHSA
GHSA-g332-j9h9-prvg: In the Linux kernel, the following vulnerability has been resolved: NFS/localio: Fix a race in nfs_local_open_fh() Once the clp->cl_uuid2025-06-18

📋Vendor Advisories

5
Ubuntu
Linux kernel (Azure) vulnerabilities2025-08-28
Ubuntu
Linux kernel (HWE) vulnerabilities2025-08-20
Ubuntu
Linux kernel vulnerabilities2025-08-18
Red Hat
kernel: Linux kernel: Privilege escalation via race condition in NFS/localio2025-06-18
Debian
CVE-2025-38028: linux - In the Linux kernel, the following vulnerability has been resolved: NFS/localio...2025
CVE-2025-38028 — Race Condition in Linux | cvebase