cbcvebase.
CVE-2025-40242
published 2025-12-04

CVE-2025-40242: In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix unlikely race in gdlm_put_lock In gdlm_put_lock(), there is a small window of…

PriorityP429high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.14%
4.0th percentile
In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix unlikely race in gdlm_put_lock In gdlm_put_lock(), there is a small window of time in which the DFL_UNMOUNT flag has been set but the lockspace hasn't been released, yet. In that window, dlm may still call gdlm_ast() and gdlm_bast(). To prevent it from dereferencing freed glock objects, only free the glock if the lockspace has actually been released.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.17.6-1 (forky)linux 6.17.6-1 (forky)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.14.247 < 4.154.15
linuxlinux>= 4.19.207 < 4.204.20
linuxlinux>= 4.4.284 < 4.54.5
linuxlinux>= 4.9.283 < 4.104.10
linuxlinux>= 5.10.67 < 5.115.11
linuxlinux>= 5.13.19 < 5.145.14
linuxlinux>= 5.14.6 < 5.155.15
linuxlinux>= 5.4.148 < 5.55.5
linuxlinux>= d1340f80f0b8066321b499a376780da00560e857 < 5fdc1474e678eea1700aa266c0b7c2c96f81dd0d5fdc1474e678eea1700aa266c0b7c2c96f81dd0d
linuxlinux>= d1340f80f0b8066321b499a376780da00560e857 < 4913592a3358f6ec366b8346b733d5e2360b08e14913592a3358f6ec366b8346b733d5e2360b08e1
linuxlinux>= d1340f80f0b8066321b499a376780da00560e857 < 279bde3bbb0ac0bad5c729dfa85983d75a5d7641279bde3bbb0ac0bad5c729dfa85983d75a5d7641
linuxlinux>= d1340f80f0b8066321b499a376780da00560e857 < 64c61b4ac645222fa7b724cef616c1f862a72a4064c61b4ac645222fa7b724cef616c1f862a72a40
linuxlinux>= d1340f80f0b8066321b499a376780da00560e857 < 28c4d9bc0708956c1a736a9e49fee71b65deee8128c4d9bc0708956c1a736a9e49fee71b65deee81
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv3.2LOW
vendor_msrc9.8CRITICAL
vendor_ubuntu7.8HIGH
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.