CVE-2025-23138: Debian Linux
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: watch_queue: fix pipe accounting mismatch Currently, watch_queue_set_size() modifies the pipe buffers charged to user->pipe_bufs without updating the pipe->nr_accounted on the pipe itself, due to the if (!pipe_has_watch_queue()) test in pipe_resize_ring(). This means that when the pipe is ultimately freed, we decrement user->pipe_bufs by something other than what than we had charged to it, potentially leading to an underflow. This in turn can cause subsequent too_many_pipe_buffers_soft() tests to fail with -EPERM. To remedy this, explicitly account for the pipe usage in watch_queue_set_size() to match the number set via account_pipe_buffers() (It's unclear why watch_queue_set_size() does not update nr_accounted; it may be due to intentional overprovisioning in watch_queue_set_size()?)
Affected products
- Debian Debian Linux: version 11.0 only
- Linux Linux Kernel: from 5.10.210, before 5.10.236 (fixed in 5.10.236); from 5.15.149, before 5.15.180 (fixed in 5.15.180); from 6.1.76, before 6.1.134 (fixed in 6.1.134); from 6.6.15, before 6.6.87 (fixed in 6.6.87); from 6.7.3, before 6.12.23 (fixed in 6.12.23); from 6.13, before 6.13.11 (fixed in 6.13.11); …
Published 2025-04-16. Last modified 2026-06-17.