CVE-2025-38396 Details
Description
In the Linux kernel, the following vulnerability has been resolved: fs: export anon_inode_make_secure_inode() and fix secretmem LSM bypass Export anon_inode_make_secure_inode() to allow KVM guest_memfd to create anonymous inodes with proper security context. This replaces the current pattern of calling alloc_anon_inode() followed by inode_init_security_anon() for creating security context manually. This change also fixes a security regression in secretmem where the S_PRIVATE flag was not cleared after alloc_anon_inode(), causing LSM/SELinux checks to be bypassed for secretmem file descriptors. As guest_memfd currently resides in the KVM module, we need to export this symbol for use outside the core kernel. In the future, guest_memfd might be moved to core-mm, at which point the symbols no longer would have to be exported. When/if that happens is still unclear.
A vulnerability in the Linux kernel's handling of anonymous inodes has been addressed. The issue arose in the secret memory (secretmem) feature, where the S_PRIVATE flag was not properly cleared, allowing Linux Security Module (LSM) and SELinux checks to be bypassed for secretmem file descriptors. This vulnerability has been resolved by exporting the anon_inode_make_secure_inode() function to enable KVM guest memory file descriptors to create anonymous inodes with the correct security context. The change replaces the previous method of manually setting the security context, thereby restoring proper LSM/SELinux enforcement for secretmem file descriptors.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/66d29d757c968d2bee9124816da5d718eb352959 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6ca45ea48530332a4ba09595767bd26d3232743b | kernel.org | Patch |
| https://git.kernel.org/stable/c/cbe4134ea4bc493239786220bd69cb8a13493190 | kernel.org | Patch |
| https://git.kernel.org/stable/c/e3eed01347721cd7a8819568161c91d538fbf229 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f94c422157f3e43dd31990567b3e5d54b3e5b32b | kernel.org | Patch |
| https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html | CVE | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 6.0, < 6.1.146 >= 6.2, < 6.6.97 >= 6.7, < 6.12.37 >= 6.13, < 6.15.6 6.16 rc1 6.16 rc2 6.16 rc3 6.16 rc4 |
CPE
Remediation
| |
| debian debian linux | 11.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Dec 23, 2025 | Initial Analysis | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Jul 25, 2025 | New CVE Received | kernel.org |