SB2025062089 - Improper locking in Linux kernel md driver
Published: June 20, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2025-38066)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the get_cache_dev_size() and cache_preresume() functions in drivers/md/dm-cache-target.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/00586b78eeb7c626a14ca13453a1631f88a7cf36
- https://git.kernel.org/stable/c/025c8f477625eb39006ded650e7d027bcfb20e79
- https://git.kernel.org/stable/c/3986ef4a9b6a0d9c28bc325d8713beba5e67586f
- https://git.kernel.org/stable/c/5da692e2262b8f81993baa9592f57d12c2703dea
- https://git.kernel.org/stable/c/c5356a5e80442131e2714d0d26bb110590e4e568
- https://git.kernel.org/stable/c/c614584c2a66b538f469089ac089457a34590c14
- https://git.kernel.org/stable/c/cc80a5cc520939d0a7d071cc4ae4b3c55ef171d0
- https://git.kernel.org/stable/c/f3128e3074e8af565cc6a66fe3384a56df87f803