Junglewise Threat Intelligence

CVE-2025-40242: Linux Kernel GFS2 use-after-free in gdlm_put_lock

CVE-2025-40242 · Severity: high · CVSS 7 · Published 2025-12-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A race condition vulnerability was identified in the Linux kernel's GFS2 file system component, which manages shared storage in clustered environments. Under specific conditions during a system unmount, the kernel might prematurely free memory while it is still being accessed by the distributed lock manager. This could lead to a system crash or potentially allow an attacker to gain unauthorized control over the system.

Technical details

A race condition exists in the gdlm_put_lock() function within the GFS2 (Global File System 2) subsystem of the Linux kernel. The vulnerability occurs because there is a timing window where the DFL_UNMOUNT flag is set, but the lockspace has not yet been fully released. During this window, the Distributed Lock Manager (DLM) may still trigger asynchronous completion (gdlm_ast) or blocking (gdlm_bast) callbacks. If the glock object is freed prematurely based on the DFL_UNMOUNT flag, these callbacks will dereference the freed memory, resulting in a use-after-free. The fix ensures the glock is only freed if the lockspace has been successfully released (indicated by an -ENODEV error from dlm_unlock). Patches have been merged into multiple stable kernel branches.

Affected products

  • Linux Linux Kernel 4.4.284, 4.9.283, 4.14.247, 4.19.207, 5.4.148 and others prior to fix

Timeline

  • 2025-12-04: disclosed: Initial CVE publication
  • 2025-12-04: advisory

References

Related threats