CVE-2025-38247

Source
https://cve.org/CVERecord?id=CVE-2025-38247
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38247.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-38247
Downstream
Published
2025-07-09T10:42:28.531Z
Modified
2026-04-02T12:47:53.374664Z
Summary
userns and mnt_idmap leak in open_tree_attr(2)
Details

In the Linux kernel, the following vulnerability has been resolved:

userns and mntidmap leak in opentree_attr(2)

Once wantmountsetattr() has returned a positive, it does require finishmountkattr() to release ->mntuserns. Failing domount_setattr() does not change that.

As the result, we can end up leaking userns and possibly mnt_idmap as well.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38247.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c4a16820d90199409c9bf01c4f794e1e9e8d8fd8
Fixed
142db4e76110dd80239f4e79810f85ea1735ad60
Fixed
0748e553df0225754c316a92af3a77fdc057b358

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38247.json"