CVE-2025-38212
published 2025-07-04CVE-2025-38212: In the Linux kernel, the following vulnerability has been resolved: ipc: fix to protect IPCS lookups using RCU syzbot reported that it discovered a…
high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
In the Linux kernel, the following vulnerability has been resolved:
ipc: fix to protect IPCS lookups using RCU
syzbot reported that it discovered a use-after-free vulnerability, [0]
[0]: https://lore.kernel.org/all/[email protected]/
idr_for_each() is protected by rwsem, but this is not enough. If it is
not protected by RCU read-critical region, when idr_for_each() calls
radix_tree_node_free() through call_rcu() to free the radix_tree_node
structure, the node will be freed immediately, and when reading the next
node in radix_tree_for_each_slot(), the already freed memory may be read.
Therefore, we need to add code to make sure that idr_for_each() is
protected within the RCU read-critical region when we call it in
shm_destroy_orphaned().
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 6.1.147-1 (bookworm) | linux 6.1.147-1 (bookworm) |
| debian | linux-6.1 | < linux 6.1.147-1 (bookworm) | linux 6.1.147-1 (bookworm) |
| linux | linux | — | — |
| linux | linux | >= b34a6b1da371ed8af1221459a18c67970f7e3d53 < 5f1e1573bf103303944fd7225559de5d8297539c | 5f1e1573bf103303944fd7225559de5d8297539c |
| linux | linux | >= b34a6b1da371ed8af1221459a18c67970f7e3d53 < b968ba8bfd9f90914957bbbd815413bf6a98eca7 | b968ba8bfd9f90914957bbbd815413bf6a98eca7 |
| linux | linux | >= b34a6b1da371ed8af1221459a18c67970f7e3d53 < 74bc813d11c30e28fc5261dc877cca662ccfac68 | 74bc813d11c30e28fc5261dc877cca662ccfac68 |
| linux | linux | >= b34a6b1da371ed8af1221459a18c67970f7e3d53 < 78297d53d3878d43c1d627d20cd09f611fa4b91d | 78297d53d3878d43c1d627d20cd09f611fa4b91d |
| linux | linux | >= b34a6b1da371ed8af1221459a18c67970f7e3d53 < 5180561afff8e0f029073c8c8117c95c6512d1f9 | 5180561afff8e0f029073c8c8117c95c6512d1f9 |
| linux | linux | >= b34a6b1da371ed8af1221459a18c67970f7e3d53 < 68c173ea138b66d7dd1fd980c9bc578a18e11884 | 68c173ea138b66d7dd1fd980c9bc578a18e11884 |
| linux | linux | >= b34a6b1da371ed8af1221459a18c67970f7e3d53 < b0b6bf90ce2699a574b3683e22c44d0dcdd7a057 | b0b6bf90ce2699a574b3683e22c44d0dcdd7a057 |
| linux | linux | >= b34a6b1da371ed8af1221459a18c67970f7e3d53 < d66adabe91803ef34a8b90613c81267b5ded1472 | d66adabe91803ef34a8b90613c81267b5ded1472 |
| linux | linux_kernel | >= 0 < 5.10.244-1 | 5.10.244-1 |
| linux | linux_kernel | >= 0 < 6.1.147-1 | 6.1.147-1 |
| linux | linux_kernel | >= 0 < 6.12.35-1 | 6.12.35-1 |
| linux | linux_kernel | >= 0 < 6.12.35-1 | 6.12.35-1 |
| linux | linux_kernel | >= 0 < 5.15.0-156.166 | 5.15.0-156.166 |
| linux | linux_kernel | >= 0 < 6.8.0-100.100 | 6.8.0-100.100 |
| linux | linux_kernel | >= 3.1 < 5.4.295 | 5.4.295 |
| linux | linux_kernel | >= 5.11 < 5.15.186 | 5.15.186 |
| linux | linux_kernel | >= 5.16 < 6.1.142 | 6.1.142 |
| linux | linux_kernel | >= 5.5 < 5.10.239 | 5.10.239 |
| linux | linux_kernel | >= 6.13 < 6.15.4 | 6.15.4 |
| linux | linux_kernel | >= 6.2 < 6.6.95 | 6.6.95 |
| linux | linux_kernel | >= 6.7 < 6.12.35 | 6.12.35 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH