RDMA/cma: Fix hang when cma_netevent_callback fails to queue_work
Published Jul 3, 2025
5.5
MEDIUMCVSS 3.1
EPSS 0.18%
Description
The cited commit fixed a crash when cma_netevent_callback was called for a cma_id while work on that id from a previous call had not yet started. The work item was re-initialized in the second call, which corrupted the work item currently in the work queue.
However, it left a problem when queue_work fails (because the item is still pending in the work queue from a previous call). In this case, cma_id_put (which is called in the work handler) is therefore not called. This results in a userspace process hang (zombie process).
Fix this by calling cma_id_put() if queue_work fails.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.1.135StatusaffectedConstraints<6.1.142
- Version 6.12.25StatusaffectedConstraints<6.12.34
- Version 6.14.4StatusaffectedConstraints<6.15
- Version 6.6.88StatusaffectedConstraints<6.6.94
- Version
-
- Version 6.15StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.15
- Version 6.1.142StatusunaffectedConstraints<=6.1.*
- Version 6.12.34StatusunaffectedConstraints<=6.12.*
- Version 6.15.3StatusunaffectedConstraints<=6.15.*
- Version 6.16StatusunaffectedConstraints<=*
- Version 6.6.94StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
Configuration 1
- ≥ 6.1.135 · < 6.1.142
- ≥ 6.6.88 · < 6.6.94
- ≥ 6.12.25 · < 6.12.34
- ≥ 6.14.4 · < 6.15
- ≥ 6.15.1 · < 6.15.3
- 6.15
- 6.15
- 6.15
- 6.15
- 6.15
- 6.15
Configuration 2
- 11.0
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (12)
- https://access.redhat.com/security/cve/CVE-2025-38151 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2376049 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-19792 Advisory
- https://git.kernel.org/stable/c/02e45168e0fd6fdc6f8f7c42c4b500857aa5efb0 Patch
- https://git.kernel.org/stable/c/1ac40736c8c4255d8417b937c9715b193f4a87b3 Patch
- https://git.kernel.org/stable/c/8b05aa3692e45b8249379dc52b14acc6a104d2e5 Patch
- https://git.kernel.org/stable/c/92a251c3df8ea1991cd9fe00f1ab0cfce18d7711 Patch
- https://git.kernel.org/stable/c/ac7897c0124066b9705ffca252a3662d54fc0c9b Patch
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html Third Party Advisory
- https://lore.kernel.org/linux-cve-announce/2025070336-CVE-2025-38151-6483@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-38151
- https://www.cve.org/CVERecord?id=CVE-2025-38151
Change history (0)
No recorded changes yet.