High severity7.8NVD Advisory· Published Jun 18, 2025· Updated Jul 30, 2026
CVE-2025-38028
CVE-2025-38028
Description
In the Linux kernel, the following vulnerability has been resolved:
NFS/localio: Fix a race in nfs_local_open_fh()
Once the clp->cl_uuid.lock has been dropped, another CPU could come in and free the struct nfsd_file that was just added. To prevent that from happening, take the RCU read lock before dropping the spin lock.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
106.14+ 8 more
- (no CPE)range: 6.14
- cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: >=6.14,<6.14.8
- cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.15:rc2:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.15:rc3:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.15:rc4:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.15:rc5:*:*:*:*:*:*
- cpe:2.3:o:linux:linux_kernel:6.15:rc6:*:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.