Junglewise Threat Intelligence

CVE-2025-38717: Linux Kernel race condition in KCM kcm_unattach

CVE-2025-38717 · Severity: high · CVSS 7.8 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability has been identified in the Linux kernel's Kernel Connection Multiplexor (KCM), a component used to improve network application performance. A race condition could allow a local attacker to cause a system crash or potentially execute unauthorized actions by triggering a timing flaw during the disconnection of network sockets. This issue primarily impacts system stability and availability.

Technical details

A race condition exists in the Linux kernel's Kernel Connection Multiplexor (KCM) module when kcm_unattach() and kcm_release() are executed concurrently. The vulnerability stems from kcm_unattach() failing to check the tx_stopped flag before calling queue_work(), which allows kcm->tx_work to be requeued after it has been synchronized but before the KCM structure is freed in kcm_done(). This leads to a use-after-free (UAF) condition. The fix replaces the manual flag check with disable_work_sync() to properly fence the workqueue. Local attackers with sufficient privileges to interact with KCM sockets can exploit this to cause a kernel panic or potentially achieve local privilege escalation.

Affected products

  • Linux Linux Kernel 4.6 to 6.12.42, 6.13 to 6.15.10, 6.16 to 6.16.1

Timeline

  • 2025-08-13: patched: Initial fix commit in mainline kernel
  • 2025-09-04: disclosed: CVE published

References

Related threats