Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-38504— io_uring/zcrx: fix pp destruction warnings

AI Predicted 3.7 Difficulty: Easy EPSS 0.13% · P3

Affected Version Matrix 6

VendorProductVersion RangeStatus
LinuxLinux34a3e60821ab9f335a58d43a88cccdbefdebdec3< ad9f1b5bed082b9c910e2a24bae0286a70846909affected
34a3e60821ab9f335a58d43a88cccdbefdebdec3< 203817de269539c062724d97dfa5af3cdf77a3ecaffected
6.15affected
< 6.15unaffected
6.15.7≤ 6.15.*unaffected
6.16≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-38504

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
io_uring/zcrx: fix pp destruction warnings
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix pp destruction warnings With multiple page pools and in some other cases we can have allocated niovs on page pool destruction. Remove a misplaced warning checking that all niovs are returned to zcrx on io_pp_zc_destroy(). It was reported before but apparently got lost.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于io_uring/zcrx中pp销毁警告不当,可能导致内存泄漏。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 34a3e60821ab9f335a58d43a88cccdbefdebdec3 ~ ad9f1b5bed082b9c910e2a24bae0286a70846909 -
LinuxLinux 6.15 -

II. Public POCs for CVE-2025-38504

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-38504

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-08-16 · 59 CVEs total

CVE-2025-385279.8 CRITICALsmb: client: fix use-after-free in cifs_oplock_break
CVE-2025-385339.8 CRITICALnet: libwx: fix the using of Rx buffer DMA
CVE-2025-385529.4 CRITICALmptcp: plug races between subflow fail and subflow creation
CVE-2025-385128.8 HIGHwifi: prevent A-MSDU attacks in mesh networks
CVE-2025-385118.8 HIGHdrm/xe/pf: Clear all LMTT pages on alloc
CVE-2025-385027.8 HIGHbpf: Fix oob access in cgroup local storage
CVE-2025-385427.8 HIGHnet: appletalk: Fix device refcount leak in atrtr_create()
CVE-2025-385327.8 HIGHnet: libwx: properly reset Rx ring descriptor
CVE-2025-385507.8 HIGHipv6: mcast: Delay put pmc->idev in mld_del_delrec()
CVE-2025-385367.8 HIGHnet: airoha: fix potential use-after-free in airoha_npu_get()
CVE-2025-385397.8 HIGHtracing: Add down_write(trace_event_sem) when adding trace event
CVE-2025-385237.5 HIGHcifs: Fix the smbd_response slab to allow usercopy
CVE-2025-385017.5 HIGHksmbd: limit repeated connections from clients with the same IP
CVE-2025-385457.5 HIGHnet: ethernet: ti: am65-cpsw-nuss: Fix skb size by accounting for skb_shared_info
CVE-2025-385267.5 HIGHice: add NULL check in eswitch lag check
CVE-2025-385257.5 HIGHrxrpc: Fix irq-disabled in local_bh_enable()
CVE-2025-385247.5 HIGHrxrpc: Fix recv-recv race of completed call
CVE-2025-385147.5 HIGHrxrpc: Fix oops due to non-existence of prealloc backlog struct
CVE-2025-385087.3 HIGHx86/sev: Use TSC_FACTOR for Secure TSC frequency calculation
CVE-2025-385477.3 HIGHiio: adc: axp20x_adc: Add missing sentinel to AXP717 ADC channel maps

Showing top 20 of 59 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-38504

No comments yet


Leave a comment