CVE-2025-23131

Source
https://cve.org/CVERecord?id=CVE-2025-23131
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-23131.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-23131
Downstream
Related
Published
2025-04-16T14:13:13.056Z
Modified
2026-08-12T03:51:47.616263533Z
Summary
dlm: prevent NPD when writing a positive value to event_done
Details

In the Linux kernel, the following vulnerability has been resolved:

dlm: prevent NPD when writing a positive value to event_done

douevent returns the value written to eventdone. In case it is a positive value, new_lockspace would undo all the work, and lockspace would not be set. __dlmnewlockspace, however, would treat that positive value as a success due to commit 8511a2728ab8 ("dlm: fix use count with multiple joins").

Down the line, devicecreatelockspace would pass that NULL lockspace to dlmfindlockspace_local, leading to a NULL pointer dereference.

Treating such positive values as successes prevents the problem. Given this has been broken for so long, this is unlikely to break userspace expectations.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/23xxx/CVE-2025-23131.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
8511a2728ab82cab398e39d019f5cf1246021c1c
Fixed
a1c41aebb184d9228a440dcb6761224e65b0e49a
Fixed
ee28d99d789b077565cbe0377374d1e826c64d93
Fixed
c7837e2c96559663c33f43da403d9cf3cf77cfa7
Fixed
7109d69bec6edce546dc870e66bd2b668a3d5549
Fixed
10b7a59814765d18d43555c9cef4eb3048b7e8a3
Fixed
b73c4ad4d387fe5bc988145bd9f1bc0de76afd5c
Fixed
8e2bad543eca5c25cd02cbc63d72557934d45f13

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-23131.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.31
Fixed
5.10.260
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.211
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.177
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.144
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.95
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.14.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-23131.json"