Junglewise Threat Intelligence

CVE-2025-38058: Linux Kernel improper locking in __legitimize_mnt

CVE-2025-38058 · Severity: medium · CVSS 5.5 · Published 2025-06-18

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's file system management could allow a local user to cause a system crash or instability. The issue occurs when the system incorrectly handles the unmounting of storage volumes, leading to internal reference counting errors. This could result in a denial-of-service condition, affecting the availability of the system.

Technical details

A race condition exists in the __legitimize_mnt() function within fs/namespace.c of the Linux kernel. The root cause is that the check for the MNT_SYNC_UMOUNT flag was performed outside of the mount_lock, allowing a race where a mount reference count (mnt_count) could be incremented after umount(2) verified the mount was not busy but before the flag was set. This leads to a leaked reference that eventually triggers a full mntput() in an unsafe context. An attacker with local access could potentially exploit this to cause a kernel panic or denial-of-service. The fix moves the MNT_SYNC_UMOUNT check under the protection of the mount_lock.

Affected products

  • Linux Linux Kernel up to 5.4.294, 5.5 to 5.10.238, 5.11 to 5.15.185, 5.16 to 6.1.141, 6.2 to 6.6.93, 6.7 to 6.12.31, 6.13 to 6.14.9

Timeline

  • 2025-06-18: disclosed
  • 2025-06-18: advisory

References

Related threats