Junglewise Threat Intelligence

CVE-2025-38722: Linux Kernel habanalabs use-after-free in export_dmabuf

CVE-2025-38722 · Severity: high · CVSS 7.8 · Published 2025-09-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A security vulnerability was identified in the Linux kernel's habanalabs driver, which manages specialized AI accelerator hardware. A flaw in how the system handles memory sharing could allow a local attacker to cause a system crash or potentially execute unauthorized actions by exploiting a race condition during file descriptor creation. This issue primarily impacts the stability and security of systems using Habana Labs accelerator cards.

Technical details

A use-after-free (UAF) vulnerability exists in the habanalabs driver within the Linux kernel's accelerator subsystem. The root cause is a race condition in export_dmabuf() where fd_install() is called via dma_buf_fd() before the kernel finishes accessing objects associated with the file descriptor. If another thread closes the file descriptor immediately after its insertion into the descriptor table, the underlying objects (such as struct file) may be destroyed while the kernel is still attempting to grab references to them. The fix reorders the operations to reserve the descriptor first and perform fd_install() only after all object setups are complete. Patches are available in stable kernel releases 6.12.43, 6.15.11, and 6.16.2.

Affected products

  • Linux Linux Kernel 5.16 to 6.12.42, 6.13 to 6.15.10, 6.16 to 6.16.1

Timeline

  • 2025-07-12: patched: Initial fix authored by Al Viro
  • 2025-09-04: disclosed: CVE-2025-38722 published

References

Related threats