PT-2025-35960 · Linux +1 · Linux Kernel +1
Syzbot
·
Published
2025-09-04
·
Updated
2025-09-04
·
CVE-2025-38687
None
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
The Linux kernel contains a use-after-free flaw within the comedi subsystem. This issue occurs due to the removal of allocated asynchronous areas while poll requests are still active, potentially leading to a use-after-free when poll entries are triggered or removed. The vulnerability is addressed by ensuring that no tasks are queued on subdevice wait queues before allowing device detachment via the `COMEDI DEVCONFIG` ioctl. The `comedi device detach()` function was refactored into `comedi device detach locked()` to ensure proper locking during the detachment process.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Related Identifiers
Affected Products
References · 15
- https://nvd.nist.gov/vuln/detail/CVE-2025-38687 · Security Note
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-38687 · Security Note
- https://security-tracker.debian.org/tracker/source-package/linux · Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2025-38687 · Vendor Advisory
- https://packages.debian.org/src:linux · Note
- https://git.kernel.org/stable/c/fe67122ba781df44a1a9716eb1dfd751321ab512 · Note
- https://git.kernel.org/stable/c/71ca60d2e631cf9c63bcbc7017961c61ff04e419 · Note
- https://git.kernel.org/stable/c/cd4286123d6948ff638ea9cd5818ae4796d5d252 · Note
- https://twitter.com/CVEnew/status/1963644654856941989 · Twitter Post
- https://git.kernel.org/stable/c/d85fac8729c9acfd72368faff1d576ec585e5c8f · Note
- https://git.kernel.org/stable/c/35b6fc51c666fc96355be5cd633ed0fe4ccf68b2 · Note
- https://git.kernel.org/stable/c/5724e82df4f9a4be62908362c97d522d25de75dd · Note
- https://git.kernel.org/stable/c/017198079551a2a5cf61eae966af3c4b145e1f3b · Note
- https://git.kernel.org/stable/c/5c4a2ffcbd052c69bbf4680677d4c4eaa5a252d4 · Note
- https://git.kernel.org/stable/c/0f989f9d05492028afd2bded4b42023c57d8a76e · Note