CVE-2025-38245 — Time-of-check Time-of-use (TOCTOU) Race Condition in Linux
Severity
7.8HIGHNVD
OSV5.6OSV3.2
EPSS
0.0%
top 94.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 9
Latest updateMar 25
Description
In the Linux kernel, the following vulnerability has been resolved:
atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister().
syzbot reported a warning below during atm_dev_register(). [0]
Before creating a new device and procfs/sysfs for it, atm_dev_register()
looks up a duplicated device by __atm_dev_lookup(). These operations are
done under atm_dev_mutex.
However, when removing a device in atm_dev_deregister(), it releases the
mutex just after removing the device from the …
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages4 packages
▶CVEListV5linux/linux64bf69ddff7637b7ed7acf9b2a823cc0ee519439 — 2a8dcee649d12f69713f2589171a1caf6d4fa439+8
Also affects: Debian Linux 11.0