CVE-2025-38720

Source
https://cve.org/CVERecord?id=CVE-2025-38720
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38720.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-38720
Downstream
Published
2025-09-04T15:33:14Z
Modified
2026-08-12T03:51:32Z
Summary
net: hibmcge: fix rtnl deadlock issue
Details

In the Linux kernel, the following vulnerability has been resolved:

net: hibmcge: fix rtnl deadlock issue

Currently, the hibmcge netdev acquires the rtnl_lock in pci_error_handlers.reset_prepare() and releases it in pci_error_handlers.reset_done().

However, in the PCI framework: pci_reset_bus - __pci_reset_slot - pci_slot_save_and_disable_locked - pci_dev_save_and_disable - err_handler->reset_prepare(dev);

In pci_slot_save_and_disable_locked(): list_for_each_entry(dev, &slot->bus->devices, bus_list) { if (!dev->slot || dev->slot!= slot) continue; pci_dev_save_and_disable(dev); if (dev->subordinate) pci_bus_save_and_disable_locked(dev->subordinate); }

This will iterate through all devices under the current bus and execute err_handler->reset_prepare(), causing two devices of the hibmcge driver to sequentially request the rtnl_lock, leading to a deadlock.

Since the driver now executes netif_device_detach() before the reset process, it will not concurrently with other netdev APIs, so there is no need to hold the rtnl_lock now.

Therefore, this patch removes the rtnl_lock during the reset process and adjusts the position of HBG_NIC_STATE_RESETTING to ensure that multiple resets are not executed concurrently.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38720.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3f5a61f6d504f55ed1a36cce044d5123d508721f
Fixed
d85a6346fd6f595c4914205762d0cdf35c004a5e
Fixed
1343a8994ca7dba78f5dd818e89d68331c21c35d
Fixed
c875503a9b9082928d7d3fc60b5400d16fbfae4e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38720.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.14.0
Fixed
6.15.11
Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.16.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-38720.json"