Home

Description

In the Linux kernel, the following vulnerability has been resolved: IB/cm: Drop lockdep assert and WARN when freeing old msg The send completion handler can run after cm_id has advanced to another message. The cm_id lock is not needed in this case, but a recent change re-used cm_free_priv_msg(), which asserts that the lock is held and WARNs if the cm_id's currently outstanding msg is different than the one being freed.

PUBLISHED Reserved 2025-04-16 | Published 2025-07-10 | Updated 2026-05-11 | Assigner Linux

Product status

Default status
unaffected

1e5159219076ddb2e44338c667c83fd1bd43dfef (git) before fc096a0cd2017cb0aa1e7fb83131410af9283910
affected

1e5159219076ddb2e44338c667c83fd1bd43dfef (git) before 7590649ee7af381a9d1153143026dec124c5798e
affected

Default status
affected

6.13
affected

Any version before 6.13
unaffected

6.15.3 (semver)
unaffected

6.16 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/fc096a0cd2017cb0aa1e7fb83131410af9283910

git.kernel.org/...c/7590649ee7af381a9d1153143026dec124c5798e

cve.org (CVE-2025-38287)

nvd.nist.gov (CVE-2025-38287)

Download JSON