Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-38151

17
FAUCET Score

CVE-2025-38151 is a Linux kernel vulnerability in the RDMA/cma component that can lead to a userspace process hang (zombie process). This occurs when the cma_netevent_callback fails to queue a work item, preventing the necessary cma_id_put call and leaving the process in an unrecoverable state. The vulnerability affects various Debian and Linux kernel versions. Rated with a CVSS score of 5.5 (MEDIUM), this vulnerability has a local attack vector and low attack complexity, requiring local privileges but no user interaction. The primary impact is a high availability impact, as it can cause system instability and resource exhaustion due to hung processes. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, indicating a low level of public awareness or concern regarding this specific CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.1.135, < 6.1.142CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.6.88, < 6.6.94CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.12.25, < 6.12.34CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.14.4, < 6.15CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.15.1, < 6.15.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 30th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2025-38151

kernel: RDMA/cma: Fix hang when cma_netevent_callback fails to queue_work

Jul 3, 2025

References

git.kernel.org / stable/c/02e45168e0fd6fdc6f8f7c42c4b500857aa5efb0
Patch
git.kernel.org / stable/c/1ac40736c8c4255d8417b937c9715b193f4a87b3
Patch
git.kernel.org / stable/c/8b05aa3692e45b8249379dc52b14acc6a104d2e5
Patch
git.kernel.org / stable/c/92a251c3df8ea1991cd9fe00f1ab0cfce18d7711
Patch
git.kernel.org / stable/c/ac7897c0124066b9705ffca252a3662d54fc0c9b
Patch
lists.debian.org / debian-lts-announce/2025/10/msg00008.html
Third Party Advisory