CVE-2025-38028 Information

Description

In the Linux kernel the following vulnerability has been resolved:

NFS/localio: Fix a race in nfs_local_open_fh()

Once the clp->cl_uuid.lock has been dropped another CPU could come in and free the struct nfsd_file that was just added. To prevent that from happening take the RCU read lock before dropping the spin lock.

Reference

https://git.kernel.org/stable/c/185a2f2ddabdcf999823f61de67f86376883920d https://git.kernel.org/stable/c/fa7ab64f1e2fdc8f2603aab8e0dd20de89cb10d9

CNNVD-202506-2163 (Published: 2025-06-18)

Share on: