PT-2025-44094 · Linux+3 · Linux Kernel+3

Published

2025-07-15

·

Updated

2026-05-26

·

CVE-2025-40027

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.1.134-syzkaller-00037-g855bd1d7d838
Description The 9p filesystem client in the Linux kernel contained a race condition where the req list could be deleted simultaneously by both the p9 read work and p9 fd cancelled functions. This occurred when a 9p client sent an invalid flush request and later cleaned it up, or when the 9p client in p9 read work canceled all pending requests. Specifically, the issue stemmed from a double deletion of a request from the req list due to concurrent access and modification of the list under a spinlock. The vulnerability was discovered by Linux Verification Center (linuxtesting.org) using Syzkaller. The fix involves updating the check in p9 fd cancelled to skip processing requests that are not in the SENT state, as any state change from SENT also removes the request from its list.
Recommendations Update the Linux kernel to version 6.1.134-syzkaller-00037-g855bd1d7d838 or later.

Exploit

Fix

Race Condition

Weakness Enumeration

Related Identifiers

AZL-68921
BDU:2025-13603
CVE-2025-40027
DLA-4379-1
DLA-4404-1
DSA-6053-1
ECHO-48F9-0365-0C4A
MGASA-2025-0309
MGASA-2025-0310
OPENSUSE-SU-2025:15702-1
OPENSUSE-SU-2025:20172-1
OPENSUSE-SU-2026:10301-1
SUSE-SU-2025:4393-1
SUSE-SU-2025:4422-1
SUSE-SU-2025:4505-1
SUSE-SU-2025:4515-1
SUSE-SU-2025:4516-1
SUSE-SU-2025:4517-1
SUSE-SU-2025:4521-1
SUSE-SU-2026:20012-1
SUSE-SU-2026:20015-1
SUSE-SU-2026:20021-1
SUSE-SU-2026:20039-1
SUSE-SU-2026:20059-1
SUSE-SU-2026:20473-1
SUSE-SU-2026:20496-1
USN-7906-1
USN-7906-2
USN-7906-3
USN-8033-1
USN-8033-2
USN-8033-3
USN-8033-4
USN-8033-5
USN-8033-6
USN-8033-7
USN-8033-8
USN-8034-1
USN-8034-2
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8141-1
USN-8163-1
USN-8163-2
USN-8165-1
USN-8243-1
USN-8261-1

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu