SB2025071151 - Improper locking in Linux kernel kernfs
Published: July 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2025-38282)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the kernfs_should_drain_open_files() function in fs/kernfs/file.c, within the kernfs_break_active_protection() function in fs/kernfs/dir.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/071d8e4c2a3b0999a9b822e2eb8854784a350f8a
- https://git.kernel.org/stable/c/2d6a67c2b3b87808a347dc1047b520a9dd177a4f
- https://git.kernel.org/stable/c/6bfb154f95d5f0ab7ed056f23aba8c1a94cb3927
- https://git.kernel.org/stable/c/6c81f1c7812c61f187bed1b938f1d2e391d503ab
- https://git.kernel.org/stable/c/72275c888f8962b406ee9c6885c79bf68cca5a63