CVE-2025-40201 Details
Description
In the Linux kernel, the following vulnerability has been resolved: kernel/sys.c: fix the racy usage of task_lock(tsk->group_leader) in sys_prlimit64() paths The usage of task_lock(tsk->group_leader) in sys_prlimit64()->do_prlimit() path is very broken. sys_prlimit64() does get_task_struct(tsk) but this only protects task_struct itself. If tsk != current and tsk is not a leader, this process can exit/exec and task_lock(tsk->group_leader) may use the already freed task_struct. Another problem is that sys_prlimit64() can race with mt-exec which changes ->group_leader. In this case do_prlimit() may take the wrong lock, or (worse) ->group_leader may change between task_lock() and task_unlock(). Change sys_prlimit64() to take tasklist_lock when necessary. This is not nice, but I don't see a better fix for -stable.
A vulnerability has been identified in the Linux kernel's handling of task locks within the sys_prlimit64() function. This issue arises because the function's use of task_lock(tsk->group_leader) can lead to race conditions. Specifically, if the specified task (tsk) is not the current task and is not a leader, it can be altered or terminated, potentially causing task_lock() to reference a freed task structure. Additionally, sys_prlimit64() can conflict with multi-threaded execution, which modifies the group leader, leading to incorrect lock management. The vulnerability affects the Linux kernel stable tree.
The vulnerability has been addressed in the Linux kernel stable tree by modifying sys_prlimit64() to use tasklist_lock when necessary, ensuring proper synchronization and preventing race conditions.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 12, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/132f827e7bac7373e1522e89709d70b43cae5342 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/19b45c84bd9fd42fa97ff80c6350d604cb871c75 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/1bc0d9315ef5296abb2c9fd840336255850ded18 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/6796412decd2d8de8ec708213bbc958fab72f143 | kernel.org | Source CodeVendor |
| https://git.kernel.org/stable/c/a15f37a40145c986cdf289a4b88390f35efdecc4 | kernel.org | Source CodeVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Linux kernel | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 30, 2026 | CVE Modified | kernel.org |
| Jun 17, 2026 | CVE Modified | kernel.org |
| Nov 12, 2025 | New CVE Received | kernel.org |
Volerion