PT-2025-30796 · Kvm+9 · Kvm+9
Published
2025-01-01
·
Updated
2026-04-20
·
CVE-2025-38396
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
The Linux kernel contains a flaw related to the handling of anonymous inodes and security contexts. A regression existed where the S PRIVATE flag was not cleared after allocating anonymous inodes, leading to a bypass of LSM/SELinux checks for secret memory file descriptors. The issue was addressed by exporting the
anon inode make secure inode() function to allow KVM guest memfd to create anonymous inodes with the correct security context. This change resolves a security regression in secret memory where LSM/SELinux checks were bypassed. The guest memfd module currently resides in the KVM module, but may be moved to core-mm in the future.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Debian
Kvm
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu