CVE-2025-38008 Details
Description
In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix race condition in unaccepted memory handling The page allocator tracks the number of zones that have unaccepted memory using static_branch_enc/dec() and uses that static branch in hot paths to determine if it needs to deal with unaccepted memory. Borislav and Thomas pointed out that the tracking is racy: operations on static_branch are not serialized against adding/removing unaccepted pages to/from the zone. Sanity checks inside static_branch machinery detects it: WARNING: CPU: 0 PID: 10 at kernel/jump_label.c:276 __static_key_slow_dec_cpuslocked+0x8e/0xa0 The comment around the WARN() explains the problem: /* * Warn about the '-1' case though; since that means a * decrement is concurrent with a first (0->1) increment. IOW * people are trying to disable something that wasn't yet fully * enabled. This suggests an ordering problem on the user side. */ The effect of this static_branch optimization is only visible on microbenchmark. Instead of adding more complexity around it, remove it altogether.
A race condition vulnerability has been identified in the Linux kernel's page allocator, specifically in the management of unaccepted memory. The issue arises because the allocator's tracking of zones with unaccepted memory is not properly synchronized, allowing concurrent modifications that can lead to inconsistencies. This flaw was highlighted by Borislav and Thomas, who noted that the static branch operations used for tracking are not serialized with the addition or removal of unaccepted pages, creating a potential ordering problem. The vulnerability was acknowledged by the kernel's static branch machinery, which issued a warning about the concurrent decrement of a static key that was not fully enabled. The problem stems from the static branch optimization, which, while beneficial in microbenchmarking, introduces unnecessary complexity and risk of race conditions.
The vulnerability has been addressed in the official Linux kernel repository. Users should upgrade to the latest stable version of the Linux kernel to mitigate this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/71dda1cb10702dc2859f00eb789b0502de2176a9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/74953f93f47a45296cc2a3fd04e2a3202ff3fa53 | kernel.org | Patch |
| https://git.kernel.org/stable/c/98fdd2f612e949c652693f6df00442c81037776d | kernel.org | Patch |
| https://git.kernel.org/stable/c/fefc075182275057ce607effaa3daa9e6e3bdc73 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.5, < 6.6.92 >= 6.7, < 6.12.30 >= 6.13, < 6.14.8 6.15 rc1 6.15 rc2 6.15 rc3 6.15 rc4 6.15 rc5 6.15 rc6 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | kernel.org |
| Nov 17, 2025 | Initial Analysis | [email protected] |
| Jun 18, 2025 | New CVE Received | kernel.org |