CVE-2025-38595
Linux Linux, linux kernel
In the Linux kernel, the following vulnerability has been resolved: xen: fix UAF in dmabuf_exp_from_pages() [dma_buf_fd() fixes; no preferences regarding the tree it goes through - up to xen folks] As soon as we'd inserted a file reference into descriptor table, another thread could close it. That's fine for the case when all we are doing is returning that descriptor to userland (it's a race, but it's a userland race and there's nothing the kernel can do about it). However, if we follow fd_install() with any kind of access to objects that would be destroyed on close (be it the struct file i...
- CVSS
- 7.8
- EPSS
- 0.18% 7.28% percentile
- CISA KEV
- Not listed
- Published
- 2025.08.20