Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-38582— RDMA/hns: Fix double destruction of rsv_qp

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于RDMA/hns模块在错误路径中可能双重销毁rsv_qp。

CVSS 7.8 · High EPSS 0.17% · P6

Possible ATT&CK Techniques 1 AI

T1059 · Command and Scripting Interpreter

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux fd8489294dd2beefb70f12ec4f6132aeec61a4d0< dab173bae3303f074f063750a8dead2550d8c782 affected
fd8489294dd2beefb70f12ec4f6132aeec61a4d0< fc8b0f5b16bab2e032b4cfcd6218d5df3b80b2ea affected
fd8489294dd2beefb70f12ec4f6132aeec61a4d0< 10b083dbba22be19baa848432b6f25aa68ab2db5 affected
fd8489294dd2beefb70f12ec4f6132aeec61a4d0< c6957b95ecc5b63c5a4bb4ecc28af326cf8f6dc8 affected
2ccf1c75d39949d8ea043d04a2e92d7100ea723d affected
d2d9c5127122745da6e887f451dd248cfeffca33 affected
dac2723d8bfa9cf5333f477741e6e5fa1ed34645 affected
60595923371c2ebe7faf82536c47eb0c967e3425 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-38582

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RDMA/hns: Fix double destruction of rsv_qp
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix double destruction of rsv_qp rsv_qp may be double destroyed in error flow, first in free_mr_init(), and then in hns_roce_exit(). Fix it by moving the free_mr_init() call into hns_roce_v2_init(). list_del corruption, ffff589732eb9b50->next is LIST_POISON1 (dead000000000100) WARNING: CPU: 8 PID: 1047115 at lib/list_debug.c:53 __list_del_entry_valid+0x148/0x240 ... Call trace: __list_del_entry_valid+0x148/0x240 hns_roce_qp_remove+0x4c/0x3f0 [hns_roce_hw_v2] hns_roce_v2_destroy_qp_common+0x1dc/0x5f4 [hns_roce_hw_v2] hns_roce_v2_destroy_qp+0x22c/0x46c [hns_roce_hw_v2] free_mr_exit+0x6c/0x120 [hns_roce_hw_v2] hns_roce_v2_exit+0x170/0x200 [hns_roce_hw_v2] hns_roce_exit+0x118/0x350 [hns_roce_hw_v2] __hns_roce_hw_v2_init_instance+0x1c8/0x304 [hns_roce_hw_v2] hns_roce_hw_v2_reset_notify_init+0x170/0x21c [hns_roce_hw_v2] hns_roce_hw_v2_reset_notify+0x6c/0x190 [hns_roce_hw_v2] hclge_notify_roce_client+0x6c/0x160 [hclge] hclge_reset_rebuild+0x150/0x5c0 [hclge] hclge_reset+0x10c/0x140 [hclge] hclge_reset_subtask+0x80/0x104 [hclge] hclge_reset_service_task+0x168/0x3ac [hclge] hclge_service_task+0x50/0x100 [hclge] process_one_work+0x250/0x9a0 worker_thread+0x324/0x990 kthread+0x190/0x210 ret_from_fork+0x10/0x18
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于RDMA/hns模块在错误路径中可能双重销毁rsv_qp。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux fd8489294dd2beefb70f12ec4f6132aeec61a4d0 ~ dab173bae3303f074f063750a8dead2550d8c782 -
Linux Linux 6.12 -

II. Public POCs for CVE-2025-38582

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-38582

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-08-19 · 59 CVEs total

CVE-2025-38561 9.8 CRITICAL ksmbd: fix Preauh_HashValue race condition
CVE-2025-38566 9.8 CRITICAL sunrpc: fix handling of server side tls alerts
CVE-2025-38560 9.3 CRITICAL x86/sev: Evict cache lines during SNP memory validation
CVE-2025-38601 8.8 HIGH wifi: ath11k: clear initialized flag for deinit-ed srng lists
CVE-2025-38600 8.8 HIGH wifi: mt76: mt7925: fix off by one in mt7925_mcu_hw_scan()
CVE-2025-38599 8.8 HIGH wifi: mt76: mt7996: Fix possible OOB access in mt7996_tx()
CVE-2025-38592 8.8 HIGH Bluetooth: hci_devcd_dump: fix out-of-bounds via dev_coredumpv
CVE-2025-38608 8.6 HIGH bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls
CVE-2025-38574 8.6 HIGH pptp: ensure minimal skb length in pptp_xmit()
CVE-2025-38571 8.2 HIGH sunrpc: fix client side handling of tls alerts
CVE-2025-38595 7.8 HIGH xen: fix UAF in dmabuf_exp_from_pages()
CVE-2025-38598 7.8 HIGH drm/amdgpu: fix use-after-free in amdgpu_userq_suspend+0x51a/0x5a0
CVE-2025-38607 7.8 HIGH bpf: handle jset (if a & b ...) as a jump in CFG computation
CVE-2025-38614 7.8 HIGH eventpoll: Fix semi-unbounded recursion
CVE-2025-38615 7.8 HIGH fs/ntfs3: cancle set bad inode after removing name fails
CVE-2025-38604 7.8 HIGH wifi: rtl818x: Kill URBs before clearing tx status queue
CVE-2025-38593 7.8 HIGH Bluetooth: hci_sync: fix double free in 'hci_discovery_filter_clear()'
CVE-2025-38586 7.8 HIGH bpf, arm64: Fix fp initialization for exception boundary
CVE-2025-38580 7.8 HIGH ext4: fix inode use after free in ext4_end_io_rsv_work()
CVE-2025-38579 7.8 HIGH f2fs: fix KMSAN uninit-value in extent_info usage

Showing top 20 of 59 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-38582

No comments yet


Leave a comment