Junglewise Threat Intelligence

CVE-2025-38687: Linux Kernel comedi use-after-free in device detachment

CVE-2025-38687 · Severity: high · CVSS 7.3 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition vulnerability has been identified in the Linux kernel's Comedi subsystem, which handles data acquisition from various hardware devices. The flaw allows the system to detach a device while data polling requests are still active, leading to a memory error known as a use-after-free. An attacker could exploit this to cause a system crash or potentially gain unauthorized access to sensitive information.

Technical details

A race condition exists in the Linux kernel Comedi subsystem between polling and detaching operations. The vulnerability is a use-after-free (UAF) caused by the `COMEDI_DEVCONFIG` ioctl handler removing the allocated async area while poll requests are still active on the `wait_queue_head`. This occurs because the system failed to verify if tasks were still queued on subdevice wait queues before detaching. An attacker with local access could trigger this UAF by initiating a device detach while concurrent poll entries are being processed. The fix involves refactoring `comedi_device_detach()` to use proper write-locking on `dev->attach_lock` to ensure all subdevices are safe to delete before proceeding.

Affected products

  • Linux Linux Kernel 2f3fdcd7ce93 to 017198079551a2a5cf61eae966af3c4b145e1f3b

Timeline

  • 2025-07-22: patched: Initial patch developed by Ian Abbott and Jens Axboe
  • 2025-09-04: disclosed: CVE published

References

Related threats