CVE-2025-38017

MEDIUM

Linux Kernel 6.14.4-6.14.8 - Denial of Service via epoll Timeout Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: fs/eventpoll: fix endless busy loop after timeout has expired After commit 0a65bc27bd64 ("eventpoll: Set epoll timeout if it's in the future"), the following program would immediately enter a busy loop in the kernel: ``` int main() { int e = epoll_create1(0); struct epoll_event event = {.events = EPOLLIN}; epoll_ctl(e, EPOLL_CTL_ADD, 0, &event); const struct timespec timeout = {.tv_nsec = 1}; epoll_pwait2(e, &event, 1, &timeout, 0); } ``` This happens because the given (non-zero) timeout of 1 nanosecond usually expires before ep_poll() is entered and then ep_schedule_timeout() returns false, but `timed_out` is never set because the code line that sets it is skipped. This quickly turns into a soft lockup, RCU stalls and deadlocks, inflicting severe headaches to the whole system. When the timeout has expired, we don't need to schedule a hrtimer, but we should set the `timed_out` variable. Therefore, I suggest moving the ep_schedule_timeout() check into the `timed_out` expression instead of skipping it. brauner: Note that there was an earlier fix by Joe Damato in response to my bug report in [1].

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (6)
linux/Kernel 6.14.4 - 6.14.8linux
Linux/Linux 0a65bc27bd645894175c059397b4916e31955fb2 - d9ec73301099ec5975505e1c3effbe768bab9490
Linux/Linux 6.14.4 - 6.14.8
Linux/Linux 99a0ad16dfd114a429df665065dcc576dad743c0 - 7631dca012593c95d36199082546a24a0058fc50
linux/linux_kernel 6.15 rc3 (4 CPE variants)
linux/linux_kernel 6.14.4 - 6.14.8
Published Jun 18, 2025
Tracked Since Feb 18, 2026