CVE-2025-40348
In the Linux kernel, the following vulnerability has been resolved: slab: Avoid race on slab->obj_exts in alloc_slab_obj_exts If two competing threads enter alloc_slab_obj_exts() and one of them fails to allocate the object extension vector, it might override the valid slab->obj_exts allocated by the other thread with OBJEXTS_ALLOC_FAIL. This will cause the thread that lost this race and expects a valid pointer to dereference a NULL pointer later on. Update slab->obj_exts atomically using cmpxchg() to avoid slab->obj_exts overrides by racing threads. Thanks for Vlastimil and Suren's help with debugging.
Affected versions
Linux kernel versions
6.12.54,
6.17.4
and later are affected. No fixed version recorded yet.
References
The following references provide additional information about CVE-2025-40348 including vendor advisories, patch commits, exploit details, and third-party analysis. Links are sourced from the NIST NVD database.
-
PatchKernel patch commithttps://git.kernel.org/stable/c/6ed8bfd24ce1cb31742b09a3eb557cd008533eec
-
PatchKernel patch commithttps://git.kernel.org/stable/c/7c34feda6a9a203c9744281f1b6671b7dad2012d
-
PatchKernel patch commithttps://git.kernel.org/stable/c/c7af5300d78460fc5037ddc77113ba3dbfe77dc0