CVE-2025-38282

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-38282
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38282.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-38282
Downstream
Related
Published
2025-07-10T08:15:26Z
Modified
2025-08-12T21:01:17Z
Summary
[none]
Details

In the Linux kernel, the following vulnerability has been resolved:

kernfs: Relax constraint in draining guard

The active reference lifecycle provides the break/unbreak mechanism but the active reference is not truly active after unbreak -- callers don't use it afterwards but it's important for proper pairing of kn->active counting. Assuming this mechanism is in place, the WARN check in kernfsshoulddrainopenfiles() is too sensitive -- it may transiently catch those (rightful) callers between kernfsunbreakactiveprotection() and kernfsput_active() as found out by Chen Ridong:

kernfs_remove_by_name_ns    kernfs_get_active // active=1
__kernfs_remove                   // active=0x80000002
kernfs_drain            ...
wait_event
//waiting (active == 0x80000001)
                kernfs_break_active_protection
                // active = 0x80000001
// continue
                kernfs_unbreak_active_protection
                // active = 0x80000002
...
kernfs_should_drain_open_files
// warning occurs
                kernfs_put_active

To avoid the false positives (mind paniconwarn) remove the check altogether. (This is meant as quick fix, I think active reference break/unbreak may be simplified with larger rework.)

References

Affected packages