๐Ÿ” CVE Alert

CVE-2025-38717

UNKNOWN 0.0

net: kcm: Fix race condition in kcm_unattach()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: net: kcm: Fix race condition in kcm_unattach() syzbot found a race condition when kcm_unattach(psock) and kcm_release(kcm) are executed at the same time. kcm_unattach() is missing a check of the flag kcm->tx_stopped before calling queue_work(). If the kcm has a reserved psock, kcm_unattach() might get executed between cancel_work_sync() and unreserve_psock() in kcm_release(), requeuing kcm->tx_work right before kcm gets freed in kcm_done(). Remove kcm->tx_stopped and replace it by the less error-prone disable_work_sync().

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Sep 4, 2025
Last Updated May 11, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
ab7ac4eb9832e32a09f4e8042705484d2fb0aad3 < c0bffbc92a1ca3960fb9cdb8e9f75a68468eb308 ab7ac4eb9832e32a09f4e8042705484d2fb0aad3 < 7275dc3bb8f91b23125ff3f47b6529935cf46152 ab7ac4eb9832e32a09f4e8042705484d2fb0aad3 < 798733ee5d5788b12e8a52db1519abc17e826f69 ab7ac4eb9832e32a09f4e8042705484d2fb0aad3 < 52565a935213cd6a8662ddb8efe5b4219343a25d
Linux / Linux
4.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c0bffbc92a1ca3960fb9cdb8e9f75a68468eb308 git.kernel.org: https://git.kernel.org/stable/c/7275dc3bb8f91b23125ff3f47b6529935cf46152 git.kernel.org: https://git.kernel.org/stable/c/798733ee5d5788b12e8a52db1519abc17e826f69 git.kernel.org: https://git.kernel.org/stable/c/52565a935213cd6a8662ddb8efe5b4219343a25d