CVE Database
/

CVE-2025-38444

Back to search

CVE-2025-38444

Published: Jul 25, 2025

Modified: May 23, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: raid10: cleanup memleak at raid10_make_request If raid10_read_request or raid10_write_request registers a new request and the REQ_NOWAIT flag is set, the code does not free the malloc from the mempool. unreferenced object 0xffff8884802c3200 (size 192): comm "fio", pid 9197, jiffies 4298078271 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 88 41 02 00 00 00 00 00 .........A...... 08 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ backtrace (crc c1a049a2): __kmalloc+0x2bb/0x450 mempool_alloc+0x11b/0x320 raid10_make_request+0x19e/0x650 [raid10] md_handle_request+0x3b3/0x9e0 __submit_bio+0x394/0x560 __submit_bio_noacct+0x145/0x530 submit_bio_noacct_nocheck+0x682/0x830 __blkdev_direct_IO_async+0x4dc/0x6b0 blkdev_read_iter+0x1e5/0x3b0 __io_read+0x230/0x1110 io_read+0x13/0x30 io_issue_sqe+0x134/0x1180 io_submit_sqes+0x48c/0xe90 __do_sys_io_uring_enter+0x574/0x8b0 do_syscall_64+0x5c/0xe0 entry_SYSCALL_64_after_hwframe+0x76/0x7e V4: changing backing tree to see if CKI tests will pass. The patch code has not changed between any versions.

VendorProductVersions

Linux

Linux

affected
39db562b3fedb93978a7e42dd216b306740959f8 - < 10c6021a609deb95f23f0cc2f89aa9d4bffb14c7
affected
c9aa889b035fca4598ae985a0f0c76ebbb547ad2 - < 9af149ca9d0dab6e59e813519d309eff62499864
affected
c9aa889b035fca4598ae985a0f0c76ebbb547ad2 - < 8fc3d7b23d139e3cbc944c15d99b3cdbed797d2d
affected
c9aa889b035fca4598ae985a0f0c76ebbb547ad2 - < 2941155d9a5ae098b480d551f3a5f8605d4f9af5
affected
c9aa889b035fca4598ae985a0f0c76ebbb547ad2 - < ed7bcd9f617e4107ac0813c516e72e6b8f6029bd

+2 more versions

Linux

Linux

affected
5.17
unaffected
0 - < 5.17
unaffected
5.15.189 - <= 5.15.*
unaffected
6.1.146 - <= 6.1.*
unaffected
6.6.99 - <= 6.6.*

+3 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now