Vulnerability Database

309,364

Total vulnerabilities in the database

CVE-2025-38002

In the Linux kernel, the following vulnerability has been resolved:

io_uring/fdinfo: grab ctx->uring_lock around io_uring_show_fdinfo()

Not everything requires locking in there, which is why the 'has_lock' variable exists. But enough does that it's a bit unwieldy to manage. Wrap the whole thing in a ->uring_lock trylock, and just return with no output if we fail to grab it. The existing trylock() will already have greatly diminished utility/output for the failure case.

This fixes an issue with reading the SQE fields, if the ring is being actively resized at the same time.

  • Published: Jun 6, 2025
  • Updated: Nov 15, 2025
  • CVE: CVE-2025-38002
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 5.5
  • AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

No CWE or OWASP classifications available.