CVE-2025-38028 — Race Condition in Linux
Severity
4.7MEDIUMNVD
OSV7.8
EPSS
0.0%
top 87.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 18
Latest updateAug 28
Description
In the Linux kernel, the following vulnerability has been resolved:
NFS/localio: Fix a race in nfs_local_open_fh()
Once the clp->cl_uuid.lock has been dropped, another CPU could come in
and free the struct nfsd_file that was just added. To prevent that from
happening, take the RCU read lock before dropping the spin lock.
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6
Affected Packages3 packages
▶CVEListV5linux/linux86e00412254a717ffd5d38dc5ec0ee1cce6281b3 — 185a2f2ddabdcf999823f61de67f86376883920d+2
Patches
🔴Vulnerability Details
5OSV▶
linux, linux-aws, linux-aws-6.14, linux-gcp, linux-gcp-6.14, linux-oracle, linux-oracle-6.14, linux-raspi, linux-realtime vulnerabilities↗2025-08-18
OSV▶
CVE-2025-38028: In the Linux kernel, the following vulnerability has been resolved: NFS/localio: Fix a race in nfs_local_open_fh() Once the clp->cl_uuid↗2025-06-18
GHSA▶
GHSA-g332-j9h9-prvg: In the Linux kernel, the following vulnerability has been resolved:
NFS/localio: Fix a race in nfs_local_open_fh()
Once the clp->cl_uuid↗2025-06-18
📋Vendor Advisories
5Debian▶
CVE-2025-38028: linux - In the Linux kernel, the following vulnerability has been resolved: NFS/localio...↗2025