CVE-2025-38411
Published: Jul 25, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: netfs: Fix double put of request If a netfs request finishes during the pause loop, it will have the ref that belongs to the IN_PROGRESS flag removed at that point - however, if it then goes to the final wait loop, that will *also* put the ref because it sees that the IN_PROGRESS flag is clear and incorrectly assumes that this happened when it called the collector. In fact, since IN_PROGRESS is clear, we shouldn't call the collector again since it's done all the cleanup, such as calling ->ki_complete(). Fix this by making netfs_collect_in_app() just return, indicating that we're done if IN_PROGRESS is removed.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 329ba1cb402ac328224965b8fc7a554a5150908e - < d18facba5a5795ad44b2a00a052e3db2fa77ab12affected 2b1424cd131cfaba4cf7040473133d26cddac088 - < 9df7b5ebead649b00bf9a53a798e4bf83a1318fd |
Linux | Linux | affected 6.15.3 - < 6.15.6 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now