PT-2025-27739 · Linux+6 · Linux Kernel+6

Published

2025-05-16

·

Updated

2026-04-20

·

CVE-2025-38154

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: A race condition exists in the Linux kernel's bpf and sockmap functionality. The issue arises when the sk->sk socket is not locked or referenced in the backlog thread, and during the call to skb send sock(), there is a race condition with the release of sk socket. This affects all types of sockets, including tcp, udp, unix, and vsock. The problem occurs because the reference count of psock becomes 0 after sock map close() is executed, leading to a panic. To resolve this, the patch increases the psock reference count to avoid race conditions, ensuring that sock map close() waits for the backlog thread to complete and cancels all pending work.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Improper Locking

Weakness Enumeration

Related Identifiers

BDU:2025-09918
CVE-2025-38154
DLA-4328-1
DSA-5973-1
ECHO-3AE2-FD35-7BCF
MGASA-2025-0218
MGASA-2025-0219
OESA-2025-2120
OESA-2025-2121
OESA-2025-2122
OESA-2026-1341
OPENSUSE-SU-2025:20081-1
RHSA-2026:3520
RHSA-2026:5690
RHSA-2026:5813
RHSA-2026:6310
RHSA-2026:7013
RHSA-2026:7100
SUSE-SU-2025:02853-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:02969-1
SUSE-SU-2025:02996-1
SUSE-SU-2025:02997-1
SUSE-SU-2025:03011-1
SUSE-SU-2025:03023-1
SUSE-SU-2025:20577-1
SUSE-SU-2025:20586-1
SUSE-SU-2025:20601-1
SUSE-SU-2025:20602-1
SUSE-SU-2025:21074-1
SUSE-SU-2025:21139-1
SUSE-SU-2025:21179-1
SUSE-SU-2025_02853-1
SUSE-SU-2025_02969-1
SUSE-SU-2025_02996-1
SUSE-SU-2025_02997-1
SUSE-SU-2025_03011-1
SUSE-SU-2025_03023-1
USN-7769-1
USN-7769-2
USN-7769-3
USN-7770-1
USN-7771-1
USN-7774-1
USN-7774-2
USN-7774-3
USN-7774-4
USN-7774-5
USN-7775-1
USN-7775-2
USN-7775-3
USN-7776-1
USN-7789-1
USN-7789-2
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu