SB20251028113 - Improper locking in Linux kernel 9p
Published: October 28, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper locking (CVE-ID: CVE-2025-40027)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the p9_fd_cancelled() function in net/9p/trans_fd.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0e0097005abc02c9f262370674f855625f4f3fb4
- https://git.kernel.org/stable/c/284e67a93b8c48952b6fc82129a8d3eb9dc73b06
- https://git.kernel.org/stable/c/448db01a48e1cdbbc31c995716a5dac1e52ba036
- https://git.kernel.org/stable/c/674b56aa57f9379854cb6798c3bbcef7e7b51ab7
- https://git.kernel.org/stable/c/716dceb19a9f8ff6c9d3aee5a771a93d6a47a0b6
- https://git.kernel.org/stable/c/94797b84cb9985022eb9cb3275c9497fbc883bb6
- https://git.kernel.org/stable/c/c1db864270eb7fea94a9ef201da0c9dc1cbab7b8