CVE Database
/

CVE-2025-38411

Back to search

CVE-2025-38411

Published: Jul 25, 2025

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: netfs: Fix double put of request If a netfs request finishes during the pause loop, it will have the ref that belongs to the IN_PROGRESS flag removed at that point - however, if it then goes to the final wait loop, that will *also* put the ref because it sees that the IN_PROGRESS flag is clear and incorrectly assumes that this happened when it called the collector. In fact, since IN_PROGRESS is clear, we shouldn't call the collector again since it's done all the cleanup, such as calling ->ki_complete(). Fix this by making netfs_collect_in_app() just return, indicating that we're done if IN_PROGRESS is removed.

VendorProductVersions

Linux

Linux

affected
329ba1cb402ac328224965b8fc7a554a5150908e - < d18facba5a5795ad44b2a00a052e3db2fa77ab12
affected
2b1424cd131cfaba4cf7040473133d26cddac088 - < 9df7b5ebead649b00bf9a53a798e4bf83a1318fd

Linux

Linux

affected
6.15.3 - < 6.15.6

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now