Use-after-free in Linux kernel - CVE-2025-38141

 

Use-after-free in Linux kernel - CVE-2025-38141

Published: July 4, 2025


Vulnerability identifier: #VU112188
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-38141
CWE-ID: CWE-416
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the dm_blk_report_zones() and dm_revalidate_zones() functions in drivers/md/dm-zone.c. A local user can escalate privileges on the system.


Affected software

Linux kernel
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Ubuntu
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kernel (Red Hat package)
linux (Ubuntu package)
linux-aws-6.14 (Ubuntu package)
linux-oem-6.14 (Ubuntu package)
linux-azure (Ubuntu package)
linux-realtime-6.14 (Ubuntu package)
linux-oracle-6.14 (Ubuntu package)
linux-raspi (Ubuntu package)

How to mitigate CVE-2025-38141

Install update from vendor's repository.

kernel (Red Hat package) - addressed in versions 5.14.0-570.96.1.el9_6, 5.14.0-611.26.1.el9_7, 6.12.0-55.65.1.el10_0
linux (Ubuntu package) - addressed in versions 6.14.0-32.32, 6.14.0-32.32.1, 6.14.0-32.32.1~24.04.1, 6.14.0-1012.12~24.04.1, 6.14.0-1013.13, 6.14.0-1016.17, 6.14.0-1016.17~24.04.1
linux-aws-6.14 (Ubuntu package) - addressed in versions 6.14.0-32.32~24.04.1, 6.14.0-1013.13~24.04.1
linux-oem-6.14 (Ubuntu package) - update to 6.14.0-1012.12
linux-azure (Ubuntu package) - update to 6.14.0-1012.12
linux-realtime-6.14 (Ubuntu package) - update to 6.14.0-1012.12~24.04.1
linux-oracle-6.14 (Ubuntu package) - update to 6.14.0-1013.13~24.04.1
linux-raspi (Ubuntu package) - update to 6.14.0-1014.14

External References

Related Security Bulletins