-
CVE-2025-40348
- EPSS 0.02%
- Veröffentlicht 16.12.2025 13:30:22
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle 416baaa9-dc9f-4396-8d5f-8c081f
- CVE-Watchlists
- Unerledigt
slab: Avoid race on slab->obj_exts in alloc_slab_obj_exts
In the Linux kernel, the following vulnerability has been resolved: slab: Avoid race on slab->obj_exts in alloc_slab_obj_exts If two competing threads enter alloc_slab_obj_exts() and one of them fails to allocate the object extension vector, it might override the valid slab->obj_exts allocated by the other thread with OBJEXTS_ALLOC_FAIL. This will cause the thread that lost this race and expects a valid pointer to dereference a NULL pointer later on. Update slab->obj_exts atomically using cmpxchg() to avoid slab->obj_exts overrides by racing threads. Thanks for Vlastimil and Suren's help with debugging.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
715b6a5b41dae39baeaa40d3386b548bb278b9c2
Version <
c7af5300d78460fc5037ddc77113ba3dbfe77dc0
Status
affected
Version
07e38a54cabd9b4de7ceb7f075f29ffa463e458a
Version <
7c34feda6a9a203c9744281f1b6671b7dad2012d
Status
affected
Version
f7381b9116407ba2a429977c80ff8df953ea9354
Version <
6ed8bfd24ce1cb31742b09a3eb557cd008533eec
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
6.12.54
Version <
6.12.56
Status
affected
Version
6.17.4
Version <
6.17.6
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.058 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|