CVE-2025-40238 — Time-of-check Time-of-use (TOCTOU) Race Condition in Linux
Severity
3.2LOWOSV
No vectorEPSS
0.0%
top 90.90%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 4
Latest updateApr 9
Description
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: Fix IPsec cleanup over MPV device
When we do mlx5e_detach_netdev() we eventually disable blocking events
notifier, among those events are IPsec MPV events from IB to core.
So before disabling those blocking events, make sure to also unregister
the devcom device and mark all this device operations as complete,
in order to prevent the other device from using invalid netdev
during future devcom events which could cause…
Affected Packages5 packages
▶CVEListV5linux/linux82f9378c443c206d3f9e45844306e5270e7e4109 — 7e212cebc863c2c7a82f480446cd731721451691+3