PT-2026-2595 · Linux · Linux Kernel

Published

2026-01-13

·

Updated

2026-04-20

·

CVE-2025-71074

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A race condition exists within the functionfs implementation, specifically in the ffs epfile open() function. This condition can occur when a file is opened and removed concurrently, potentially leading to a use-after-free condition on subsequent read or write operations. The issue stems from the misuse of ffs->opened and inconsistencies in atomic operations. Specifically, the use of atomic dec and test() versus atomic add return() creates a window where an object remains visible despite being freed. The vulnerability is addressed by serializing openers on ffs->mutex, utilizing atomic inc not zero() for dynamic files, marking inodes of dynamic files upon removal, and verifying file state during the open process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2025-71074
ECHO-9A63-FDF2-1287

Affected Products

Linux Kernel