CVE-2025-38524
Last modified
CVE-2025-38524 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix recv-recv race of completed call If a call receives an event (such as incoming data), the call gets placed on the socket's queue and a thread in recvmsg can be awakened to go and process it. Once the thread has picked up the call off of the queue, further events will cause it to be requeued, and once the socket lock is dropped (recvmsg uses call->user_mutex to allow the socket to be used in parallel), a second thread can come in and its recvmsg can pop the call off the socket queue again. In such a case, the first thread will be receiving stuff from the call and the second thread will be blocked on call->user_mutex. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix recv-recv race of completed call If a call receives an event (such as incoming data), the call gets placed on the socket's queue and a thread in recvmsg can be awakened to go and process it. Once the thread has picked up the call off of the queue, further events will cause it to be requeued, and once the socket lock is dropped (recvmsg uses call->user_mutex to allow the socket to be used in parallel), a second thread can come in and its recvmsg can pop the call off the socket queue again. In such a case, the first thread will be receiving stuff from the call and the second thread will be blocked on call->user_mutex. The first thread can, at this point, process both the event that it picked call for and the event that the second thread picked the call for and may see the call terminate - in which case the call will be "released", decoupling the call from the user call ID assigned to it (RXRPC_USER_CALL_ID in the control message). The first thread will return okay, but then the second thread will wake up holding the user_mutex and, if it sees that the call has been released by the first thread, it will BUG thusly: kernel BUG at net/rxrpc/recvmsg.c:474! Fix this by just dequeuing the call and ignoring it if it is seen to be already released. We can't tell userspace about it anyway as the user call ID has become stale.
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | >= 4.9, < 6.6.100 | — |
| Linux | Linux Kernel | >= 6.7, < 6.12.40 | — |
| Linux | Linux Kernel | >= 6.13, < 6.15.8 | — |
| Linux | Linux Kernel | 6.16 | Rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2025-38524?
How severe is CVE-2025-38524?
How do I fix CVE-2025-38524?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-38519In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-3852The WPshop 2 – E-Commerce plugin for WordPress is vulnerable…8.8
- CVE-2025-38520In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38521In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2025-38522In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38523In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38525In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38526In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38527In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-38528In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-38529In the Linux kernel, the following vulnerability has been re…7.1
- CVE-2025-3853The WPshop 2 – E-Commerce plugin for WordPress is vulnerable…6.5
Are you affected by CVE-2025-38524?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
