cbcvebase.
CVE-2025-40203
published 2025-11-12

CVE-2025-40203: In the Linux kernel, the following vulnerability has been resolved: listmount: don't call path_put() under namespace semaphore Massage listmount() and make…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.14%
3.6th percentile
In the Linux kernel, the following vulnerability has been resolved: listmount: don't call path_put() under namespace semaphore Massage listmount() and make sure we don't call path_put() under the namespace semaphore. If we put the last reference we're fscked.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.6-1 (forky)linux 6.17.6-1 (forky)
linuxlinux
linuxlinux>= b4c2bea8ceaa50cd42a8f73667389d801a3ecf2d < 659874b7ee4976ad9ce476e07fd36bc67b3537f1659874b7ee4976ad9ce476e07fd36bc67b3537f1
linuxlinux>= b4c2bea8ceaa50cd42a8f73667389d801a3ecf2d < 9c80da26fda2fdcaac7f92b5908875b3108830ff9c80da26fda2fdcaac7f92b5908875b3108830ff
linuxlinux>= b4c2bea8ceaa50cd42a8f73667389d801a3ecf2d < c1f86d0ac322c7e77f6f8dbd216c65d39358ffc0c1f86d0ac322c7e77f6f8dbd216c65d39358ffc0
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.13.0 < 6.17.46.17.4
linuxlinux_kernel>= 6.8.0 < 6.12.546.12.54
ubuntulinux-aws
ubuntulinux-oracle

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.8MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.