CVE-2025-38551

In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix recursived rtnl_lock() during probe() The deadlock appears in a stack trace like: virtnet_probe() rtnl_lock() virtio_config_changed_work() netdev_notify_peers() rtnl_lock() It happens if the VMM sends a VIRTIO_NET_S_ANNOUNCE request while the virtio-net driver is still probing. The config_work in probe() will get scheduled until virtnet_open() enables the config change notification via virtio_config_driver_enable().
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc6:*:*:*:*:*:*

History

18 Nov 2025, 18:10

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/3859f137b3c1fa1f0031d54263234566bdcdd7aa - () https://git.kernel.org/stable/c/3859f137b3c1fa1f0031d54263234566bdcdd7aa - Patch
References () https://git.kernel.org/stable/c/4e7c46362550b229354aeb52038f414e231b0037 - () https://git.kernel.org/stable/c/4e7c46362550b229354aeb52038f414e231b0037 - Patch
References () https://git.kernel.org/stable/c/be5dcaed694e4255dc02dd0acfe036708c535def - () https://git.kernel.org/stable/c/be5dcaed694e4255dc02dd0acfe036708c535def - Patch
CWE CWE-667
First Time Linux
Linux linux Kernel
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:o:linux:linux_kernel:6.16:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.16:rc4:*:*:*:*:*:*

18 Aug 2025, 20:16

Type Values Removed Values Added
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: virtio-net: corrección de rtnl_lock() recursivo durante probe(). El interbloqueo aparece en un seguimiento de pila como: virtnet_probe() rtnl_lock() virtio_config_changed_work() netdev_notify_peers() rtnl_lock(). Esto ocurre si el VMM envía una solicitud VIRTIO_NET_S_ANNOUNCE mientras el controlador de virtio-net sigue sondeando. config_work en probe() se programará hasta que virtnet_open() habilite la notificación de cambios de configuración mediante virtio_config_driver_enable().

16 Aug 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-16 12:15

Updated : 2025-11-18 18:10


NVD link : CVE-2025-38551

Mitre link : CVE-2025-38551

CVE.ORG link : CVE-2025-38551


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
CWE-667

Improper Locking