In the Linux kernel, the following vulnerability has been resolved:
net/9p: use a dedicated spinlock for trans_fd
Shamelessly copying the explanation from Tetsuo Handa's suggested patch[1] (slightly reworded): syzbot is reporting inconsistent lock state in p9_req_put()[2], for p9_tag_remove() from p9_req_put() from IRQ context is using spin_lock_irqsave() on "struct p9_client"->lock but trans_fd (not from IRQ context) is using spin_lock().
Since the locks actually protect different things in client.c and in trans_fd.c, just replace trans_fd.c's lock by a new one specific to the transport (client.c's protect the idr for fid/tag allocations, while trans_fd.c's protects its own req list and request status field that acts as the transport's state machine)
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | May 5, 2025 | May 1, 2025 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 1, 2025 |
| Ubuntu | — | Upgrade linux-gkeUpgrade linux-gcpUpgrade linux-awsUpgrade linux-realtimeUpgrade linux-riscv-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-oracleUpgrade linux-gcp-5.15Upgrade linux-aws-5.15Upgrade linux-bluefieldUpgrade linux-nvidiaUpgrade linux-kvmUpgrade linux-hwe-5.15Upgrade linux-raspiUpgrade linux-azureUpgrade linux-intel-iotgUpgrade linux-intel-iotg-5.15Upgrade linux-intel-iot-realtimeUpgrade linux-gkeopUpgrade linuxUpgrade linux-lowlatencyUpgrade linux-ibmUpgrade linux-oracle-5.15Upgrade linux-azure-5.15Upgrade linux-azure-fde-5.15Upgrade linux-nvidia-tegra-5.15 | May 8, 2025 | May 1, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub