CVE-2025-38383

Source
https://cve.org/CVERecord?id=CVE-2025-38383
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38383.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38383
Downstream
Related
Published
2025-07-25T12:53:24.578Z
Modified
2026-03-12T02:17:49.148915Z
Summary
mm/vmalloc: fix data race in show_numa_info()
Details

In the Linux kernel, the following vulnerability has been resolved:

mm/vmalloc: fix data race in shownumainfo()

The following data-race was found in shownumainfo():

================================================================== BUG: KCSAN: data-race in vmallocinfoshow / vmallocinfoshow

read to 0xffff88800971fe30 of 4 bytes by task 8289 on cpu 0: shownumainfo mm/vmalloc.c:4936 [inline] vmallocinfoshow+0x5a8/0x7e0 mm/vmalloc.c:5016 seqreaditer+0x373/0xb40 fs/seqfile.c:230 procregreaditer+0x11e/0x170 fs/proc/inode.c:299 ....

write to 0xffff88800971fe30 of 4 bytes by task 8287 on cpu 1: shownumainfo mm/vmalloc.c:4934 [inline] vmallocinfoshow+0x38f/0x7e0 mm/vmalloc.c:5016 seqreaditer+0x373/0xb40 fs/seqfile.c:230 procregreaditer+0x11e/0x170 fs/proc/inode.c:299 ....

value changed: 0x0000008f -> 0x00000000

According to this report,there is a read/write data-race because m->private is accessible to multiple CPUs. To fix this, instead of allocating the heap in procvmallocinit() and passing the heap address to m->private, vmallocinfoshow() should allocate the heap.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38383.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8e1d743f2c2671aa54f6f91a2b33823f92512870
Fixed
ead91de35d9cd5c4f80ec51e6020f342079170af
Fixed
5c966f447a584ece3c70395898231aeb56256ee7
Fixed
5c5f0468d172ddec2e333d738d2a1f85402cf0bc

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38383.json"