-
CVE-2025-40201
- EPSS 0.03%
- Veröffentlicht 12.11.2025 21:56:34
- Zuletzt bearbeitet 14.11.2025 16:42:30
- Quelle 416baaa9-dc9f-4396-8d5f-8c081f
- CVE-Watchlists
- Unerledigt
In the Linux kernel, the following vulnerability has been resolved: kernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths The usage of task_lock(tsk->group_leader) in sys_prlimit64()->do_prlimit() path is very broken. sys_prlimit64() does get_task_struct(tsk) but this only protects task_struct itself. If tsk != current and tsk is not a leader, this process can exit/exec and task_lock(tsk->group_leader) may use the already freed task_struct. Another problem is that sys_prlimit64() can race with mt-exec which changes ->group_leader. In this case do_prlimit() may take the wrong lock, or (worse) ->group_leader may change between task_lock() and task_unlock(). Change sys_prlimit64() to take tasklist_lock when necessary. This is not nice, but I don't see a better fix for -stable.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version <
1bc0d9315ef5296abb2c9fd840336255850ded18
Version
18c91bb2d87268d23868bf13508f5bc9cf04e89a
Status
affected
Version <
132f827e7bac7373e1522e89709d70b43cae5342
Version
18c91bb2d87268d23868bf13508f5bc9cf04e89a
Status
affected
Version <
19b45c84bd9fd42fa97ff80c6350d604cb871c75
Version
18c91bb2d87268d23868bf13508f5bc9cf04e89a
Status
affected
Version <
6796412decd2d8de8ec708213bbc958fab72f143
Version
18c91bb2d87268d23868bf13508f5bc9cf04e89a
Status
affected
Version <
a15f37a40145c986cdf289a4b88390f35efdecc4
Version
18c91bb2d87268d23868bf13508f5bc9cf04e89a
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.18
Status
affected
Version <
5.18
Version
0
Status
unaffected
Version <=
6.1.*
Version
6.1.157
Status
unaffected
Version <=
6.6.*
Version
6.6.113
Status
unaffected
Version <=
6.12.*
Version
6.12.54
Status
unaffected
Version <=
6.17.*
Version
6.17.4
Status
unaffected
Version <=
*
Version
6.18
Status
unaffected
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.064 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|