Junglewise Threat Intelligence

CVE-2025-38675: Linux Kernel race condition in xfrm_state_find

CVE-2025-38675 · Severity: high · CVSS 7.8 · Published 2025-08-22

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's networking subsystem, specifically within the component responsible for managing secure IP communication (IPsec). Under certain conditions involving high system activity, the kernel may attempt to access uninitialized memory, which can lead to system instability or a complete crash. This could allow a local user to disrupt system operations or potentially gain unauthorized access to sensitive information.

Technical details

A race condition exists in the xfrm_state_find function within net/xfrm/xfrm_state.c of the Linux kernel. The vulnerability is triggered by task preemption during an XFRM state lookup; if a process is moved to a different CPU after starting a lookup but before completion, it may jump to an 'acquire' code block that utilizes the state_ptrs structure before it has been initialized. This leads to an uninitialized pointer dereference or use. The fix involves moving the initialization of state_ptrs to occur immediately after the RCU read lock is acquired, ensuring the pointers are valid regardless of preemption or the specific code path taken during the lookup. Patches have been released for multiple stable kernel branches including 6.12.y and 6.15.y.

Affected products

  • Linux Linux Kernel 6.12.13 to 6.12.41, 6.13.2 to 6.15.9, 6.14, 6.16-rc1 to 6.16-rc7

Timeline

  • 2025-08-22: disclosed
  • 2025-08-22: advisory
  • 2025-08-01: patched: Patched in stable branches via commits 463562f, 6bf2daa, and 94d077c

References

Related threats