CVE-2025-38151: Debian Linux
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: RDMA/cma: Fix hang when cma_netevent_callback fails to queue_work The cited commit fixed a crash when cma_netevent_callback was called for a cma_id while work on that id from a previous call had not yet started. The work item was re-initialized in the second call, which corrupted the work item currently in the work queue. However, it left a problem when queue_work fails (because the item is still pending in the work queue from a previous call). In this case, cma_id_put (which is called in the work handler) is therefore not called. This results in a userspace process hang (zombie process). Fix this by calling cma_id_put() if queue_work fails.
Affected products
- Debian Debian Linux: version 11.0 only
- Linux Linux Kernel: from 6.1.135, before 6.1.142 (fixed in 6.1.142); from 6.6.88, before 6.6.94 (fixed in 6.6.94); from 6.12.25, before 6.12.34 (fixed in 6.12.34); from 6.14.4, before 6.15 (fixed in 6.15); from 6.15.1, before 6.15.3 (fixed in 6.15.3); version 6.15 only
Published 2025-07-03. Last modified 2026-06-17.