CVE-2025-38028

MEDIUM

Linux Kernel 6.14-6.14.8 - Race Condition in NFS Local Open File Handle

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: NFS/localio: Fix a race in nfs_local_open_fh() Once the clp->cl_uuid.lock has been dropped, another CPU could come in and free the struct nfsd_file that was just added. To prevent that from happening, take the RCU read lock before dropping the spin lock.

Scores

CVSS v3 4.7
EPSS 0.0010
EPSS Percentile 1.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-362
Status published
Products (9)
linux/Kernel 6.14.0 - 6.14.8linux
Linux/Linux < 6.14
Linux/Linux 6.14
Linux/Linux 6.14.8 - 6.14.*
Linux/Linux 6.15
Linux/Linux 86e00412254a717ffd5d38dc5ec0ee1cce6281b3 - 185a2f2ddabdcf999823f61de67f86376883920d
Linux/Linux 86e00412254a717ffd5d38dc5ec0ee1cce6281b3 - fa7ab64f1e2fdc8f2603aab8e0dd20de89cb10d9
linux/linux_kernel 6.15 rc1 (6 CPE variants)
linux/linux_kernel 6.14 - 6.14.8
Published Jun 18, 2025
Tracked Since Feb 18, 2026