Junglewise Threat Intelligence

CVE-2025-40048: Linux Kernel race condition in uio_hv_generic driver

CVE-2025-40048 · Severity: high · CVSS 7.5 · Published 2025-10-28

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Hyper-V generic driver can cause virtual machines to stop responding. This occurs because the system may incorrectly ignore signals (interrupts) needed to process incoming data, leading to a permanent hang of the affected service. This impacts the availability of applications relying on these specific network or storage channels in cloud environments.

Technical details

A race condition exists in the uio_hv_generic driver within the Linux kernel's VMBus implementation. The driver was incorrectly managing the inbound ring buffer's interrupt_mask, which is intended to be controlled exclusively by userspace. When the driver sets the mask to 1 (disabled) concurrently with userspace operations, the host may place messages in the ring buffer without triggering an interrupt. If userspace subsequently enables interrupts and waits via pread(), it may hang indefinitely because the host only generates interrupts on empty-to-not-empty transitions. The fix involves removing driver-level logic that modifies the interrupt_mask, ensuring userspace retains full control. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux 95096f2fbd10 to 540aac117eaea5723cef5e4cbf3035c4ac654d92; 65d40acd911c7011745cbbd2aaac34eb5266d11e; a44f61f878f32071d6378e8dd7c2d47f9490c8f7; 01ce972e6f9974a7c76943bcb7e93746917db83a; 2af39ab5e6dc46b835a52e80a22d0cad430985e3; 37bd91f22794dc05436130d6983302cb90ecfe7e; e29587c07537929684faa365027f4b0d87521e1b; b15b7d2a1b09ef5428a8db260251897405a19496

Timeline

  • 2025-08-28: other: Patch authored
  • 2025-10-15: patched: Patch committed to stable branches
  • 2025-10-28: disclosed: Vulnerability published

References