Junglewise Threat Intelligence

CVE-2025-38129: Linux kernel use-after-free in page_pool_recycle_in_ring

CVE-2025-38129 · Severity: high · CVSS 7.8 · Published 2025-07-03

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was found in the Linux kernel's networking subsystem that could allow a local user to crash the system or potentially execute unauthorized code. The issue occurs when the system incorrectly manages memory while recycling network data buffers, leading to a 'use-after-free' condition. This could impact system stability and the security of data being processed by the network stack.

Technical details

A use-after-free (UAF) vulnerability exists in net/core/page_pool.c within the page_pool_recycle_in_ring function. The root cause is a race condition where a page_pool object can be freed while it is still attempting to recycle the last page in its ring buffer. Specifically, the page_pool_release process can proceed to destroy the pool while a producer is still holding a lock or accessing the ring structure. An attacker with local access could exploit this to trigger a kernel crash or achieve arbitrary code execution. The fix introduces a producer-lock barrier in page_pool_release to ensure all recycling operations are complete before the pool is destroyed.

Affected products

  • Linux Linux kernel 4.18 to 6.13-rc3

Timeline

  • 2025-05-27: patched: Initial patch submitted by Dong Chenchen
  • 2025-07-03: disclosed: CVE published

References

Related threats