Fiche vulnérabilité
CVE-2025-38393 : faille moyenne linux linux kernel (CVSS 4.7)
Description
In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Fix a race to wake on NFS_LAYOUT_DRAIN We found a few different systems hung up in writeback waiting on the same page lock, and one task waiting on the NFS_LAYOUT_DRAIN bit in pnfs_update_layout(), however the pnfs_layout_hdr's plh_outstanding count was zero. It seems most likely that this is another race between the waiter and waker similar to commit ed0172af5d6f ("SUNRPC: Fix a race to wake a sync task"). Fix it up by applying the advised barrier.
En bref
- Sévérité
- Moyenne (CVSS 4.7)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 25 juil. 2025
- Dernière mise à jour
- 30 juil. 2026
Produits concernés
- linux linux kernel
- debian debian linux
Références
- Fiche CVE-2025-38393 sur le NVD (NIST)
- git.kernel.org/stable/c/08287df60bac5b008b6bcdb03053988335d3d…
- git.kernel.org/stable/c/1f4da20080718f258e189a2c5f515385fa393…
- git.kernel.org/stable/c/864a54c1243ed3ca60baa4bc492dede1361f4…
- git.kernel.org/stable/c/8846fd02c98da8b79e6343a20e6071be6f372…
- git.kernel.org/stable/c/8ca65fa71024a1767a59ffbc6a6e2278af847…
- git.kernel.org/stable/c/c01776287414ca43412d1319d2877cbad6544…
- git.kernel.org/stable/c/e4b13885e7ef1e64e45268feef1e5f0707c47…
- lists.debian.org/debian-lts-announce/2025/10/msg00007.html
- lists.debian.org/debian-lts-announce/2025/10/msg00008.html
- cert-portal.siemens.com/productcert/html/ssa-082556.html