CVE-2025-38245 describes a race condition in the Linux kernel's ATM subsystem, specifically affecting the atm_dev_deregister() function. This vulnerability impacts various Linux distributions, including Debian and Ubuntu, where the kernel versions are susceptible. The vulnerability has a CVSS score of 7.8 (High), indicating a local attack vector with low complexity and potential for high impact on confidentiality, integrity, and availability. The issue arises because the atm_dev_mutex is released prematurely, creating a window where procfs/sysfs entries for a device might still exist after the device itself is removed from the list, leading to a warning and potential system instability. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Despite this, the vulnerability has garnered significant community discussion and media coverage, suggesting a high level of awareness and concern within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.16, < 5.4.296CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.240CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.187CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.143CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.96CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Linux kernel (Azure) vulnerabilities
Mar 25, 2026Linux kernel (Azure FIPS) vulnerabilities
Mar 4, 2026Linux kernel (Azure) vulnerabilities
Mar 4, 2026Linux kernel (Xilinx) vulnerabilities
Feb 24, 2026Linux kernel (IBM) vulnerabilities
Feb 24, 2026HP ThinPro 8.1 SP9 Security Updates
Feb 2, 2026kernel: Linux kernel: Denial of Service in ATM subsystem due to a race condition
Jul 9, 2025atm: Release atm_dev_mutex after removing procfs in atm_dev_deregister().
Jul 8, 2025