CVE-2025-38393: Debian Linux

Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: NFSv4/pNFS: Fix a race to wake on NFS_LAYOUT_DRAIN We found a few different systems hung up in writeback waiting on the same page lock, and one task waiting on the NFS_LAYOUT_DRAIN bit in pnfs_update_layout(), however the pnfs_layout_hdr's plh_outstanding count was zero. It seems most likely that this is another race between the waiter and waker similar to commit ed0172af5d6f ("SUNRPC: Fix a race to wake a sync task"). Fix it up by applying the advised barrier.

Affected products

  • Debian Debian Linux: version 11.0 only
  • Linux Linux Kernel: from 5.10.124, before 5.10.240 (fixed in 5.10.240); from 5.15.49, before 5.15.187 (fixed in 5.15.187); from 5.18.6, before 5.19 (fixed in 5.19); from 5.19.1, before 6.1.144 (fixed in 6.1.144); from 6.2, before 6.6.97 (fixed in 6.6.97); from 6.7, before 6.12.37 (fixed in 6.12.37); …

Published 2025-07-25. Last modified 2026-07-30.