CVE-2025-40061
Last modified
CVE-2025-40061 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix race in do_task() when draining When do_task() exhausts its iteration budget (!ret), it sets the state to TASK_STATE_IDLE to reschedule, without a secondary check on the current task->state. This can overwrite the TASK_STATE_DRAINING state set by a concurrent call to rxe_cleanup_task() or rxe_disable_task(). While state changes are protected by a spinlock, both rxe_cleanup_task() and rxe_disable_task() release the lock while waiting for the task to finish draining in the while(!is_done(task)) loop. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix race in do_task() when draining When do_task() exhausts its iteration budget (!ret), it sets the state to TASK_STATE_IDLE to reschedule, without a secondary check on the current task->state. This can overwrite the TASK_STATE_DRAINING state set by a concurrent call to rxe_cleanup_task() or rxe_disable_task(). While state changes are protected by a spinlock, both rxe_cleanup_task() and rxe_disable_task() release the lock while waiting for the task to finish draining in the while(!is_done(task)) loop. The race occurs if do_task() hits its iteration limit and acquires the lock in this window. The cleanup logic may then proceed while the task incorrectly reschedules itself, leading to a potential use-after-free. This bug was introduced during the migration from tasklets to workqueues, where the special handling for the draining case was lost. Fix this by restoring the original pre-migration behavior. If the state is TASK_STATE_DRAINING when iterations are exhausted, set cont to 1 to force a new loop iteration. This allows the task to finish its work, so that a subsequent iteration can reach the switch statement and correctly transition the state to TASK_STATE_DRAINED, stopping the task as intended.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= 9b4b7c1f9f54120940e243251e2b1407767b3381, < 85288bcf7ffe11e7b036edf91937bc62fd384076; >= 9b4b7c1f9f54120940e243251e2b1407767b3381, < 52edccfb555142678c836c285bf5b4ec760bd043; >= 9b4b7c1f9f54120940e243251e2b1407767b3381, < 660b6959c4170637f5db2279d1f71af33a49e49b; >= 9b4b7c1f9f54120940e243251e2b1407767b3381, < 8ca7eada62fcfabf6ec1dc7468941e791c1d8729 |
| Linux | Linux | 6.5 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-40061?
How severe is CVE-2025-40061?
How do I fix CVE-2025-40061?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-40056In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40057In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40058In the Linux kernel, the following vulnerability has been re…8.8
- CVE-2025-40059In the Linux kernel, the following vulnerability has been re…
- CVE-2025-4006A vulnerability classified as critical has been found in you…5.1
- CVE-2025-40060In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40062In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40063In the Linux kernel, the following vulnerability has been re…7
- CVE-2025-40064In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2025-40065In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40066In the Linux kernel, the following vulnerability has been re…
- CVE-2025-40067In the Linux kernel, the following vulnerability has been re…7.8
Are you affected by CVE-2025-40061?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
