Skip to main content
EPSS 0.1%top 95%

Linux aws: In the Linux kernel, the following vulnerability has been resolved: net/9p: fix double req put in p9_fd_cancelled Syzkaller reports a KASAN issue as… (CVE-2025-40027)

0
Medium
Published: 10/28/2025 (10/28/2025, 10:15:00 UTC)
Source: GCVE Database
Product: linux-aws

Description

In the Linux kernel, the following vulnerability has been resolved: net/9p: fix double req put in p9_fd_cancelled Syzkaller reports a KASAN issue as below: general protection fault, probably for non-canonical address 0xfbd59c0000000021: 0000 [#1] PREEMPT SMP KASAN NOPTI KASAN: maybe wild-memory-access in range [0xdead000000000108-0xdead00000000010f] CPU: 0 PID: 5083 Comm: syz-executor.2 Not tainted 6.1.134-syzkaller-00037-g855bd1d7d838 #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:__list_del include/linux/list.h:114 [inline] RIP: 0010:__list_del_entry include/linux/list.h:137 [inline] RIP: 0010:list_del include/linux/list.h:148 [inline] RIP: 0010:p9_fd_cancelled+0xe9/0x200 net/9p/trans_fd.c:734 Call Trace: <TASK> p9_client_flush+0x351/0x440 net/9p/client.c:614 p9_client_rpc+0xb6b/0xc70 net/9p/client.c:734 p9_client_version net/9p/client.c:920 [inline] p9_client_create+0xb51/0x1240 net/9p/client.c:1027 v9fs_session_init+0x1f0/0x18f0 fs/9p/v9fs.c:408 v9fs_mount+0xba/0xcb0 fs/9p/vfs_super.c:126 legacy_get_tree+0x108/0x220 fs/fs_context.c:632 vfs_get_tree+0x8e/0x300 fs/super.c:1573 do_new_mount fs/namespace.c:3056 [inline] path_mount+0x6a6/0x1e90 fs/namespace.c:3386 do_mount fs/namespace.c:3399 [inline] __do_sys_mount fs/namespace.c:3607 [inline] __se_sys_mount fs/namespace.c:3584 [inline] __x64_sys_mount+0x283/0x300 fs/namespace.c:3584 do_syscall_x64 arch/x86/entry/common.c:51 [inline] do_syscall_64+0x35/0x80 arch/x86/entry/common.c:81 entry_SYSCALL_64_after_hwframe+0x6e/0xd8 This happens because of a race condition between: - The 9p client sending an invalid flush request and later cleaning it up; - The 9p client in p9_read_work() canceled all pending requests. Thread 1 Thread 2 ... p9_client_create() ... p9_fd_create() ... p9_conn_create() ... // start Thread 2 INIT_WORK(&m->rq, p9_read_work); p9_read_work() ... p9_client_rpc() ... ... p9_conn_cancel() ... spin_lock(&m->req_lock); ... p9_fd_cancelled() ... ... spin_unlock(&m->req_lock); // status rewrite p9_client_cb(m->client, req, REQ_STATUS_ERROR) // first remove list_del(&req->req_list); ... spin_lock(&m->req_lock) ... // second remove list_del(&req->req_list); spin_unlock(&m->req_lock) ... Commit 74d6a5d56629 ("9p/trans_fd: Fix concurrency del of req_list in p9_fd_cancelled/p9_read_work") fixes a concurrency issue in the 9p filesystem client where the req_list could be deleted simultaneously by both p9_read_work and p9_fd_cancelled functions, but for the case where req->status equals REQ_STATUS_RCVD. Update the check for req->status in p9_fd_cancelled to skip processing not just received requests, but anything that is not SENT, as whatever changed the state from SENT also removed the request from its list. Found by Linux Verification Center (linuxtesting.org) with Syzkaller. [updated the check from status == RECV || status == ERROR to status != SENT]

CVSS v3.1

Score 7.8high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected software

Affected versions
<5.15.0-1100.107~20.04.2<5.15.0-1110.119~20.04.1<5.15.0-1100.109~20.04.1<5.15.0-170.180~20.04.3<5.15.0-1094.97~20.04.1

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 16:10:08 UTC

Technical Analysis

CVE-2025-40027 addresses a concurrency bug in the Linux kernel 9p filesystem client where a race condition between the p9_fd_cancelled and p9_read_work functions could cause a double deletion of the same request from the req_list. This occurs when an invalid flush request is sent and later cleaned up concurrently with cancellation of all pending requests. The double removal leads to a general protection fault and potential memory corruption detected by KASAN. The patch modifies the status check in p9_fd_cancelled to skip processing requests not in the SENT state, ensuring the request list is not concurrently modified twice.

Potential Impact

This vulnerability can cause a general protection fault and kernel memory corruption, potentially leading to denial of service or escalation of privileges due to unstable kernel state. The CVSS vector indicates high impact on confidentiality, integrity, and availability, but no known exploits in the wild have been reported.

Mitigation Recommendations

A fix has been committed to the Linux kernel (commit 74d6a5d56629) addressing the concurrency issue in the 9p filesystem client. Users should apply the official kernel update containing this patch. Since this is a kernel-level vulnerability, upgrading to a patched kernel version is the recommended mitigation. Patch status is not explicitly stated in the provided data; check the vendor or kernel mailing list advisories for the exact fixed kernel versions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-wv8v-rm52-wq8h
Osv Schema Version
1.4.0
Aliases
["CVE-2025-40027"]
Database Specific Severity
HIGH
Cvss Version
3.1

Threat ID: 6a6b72d79c2644c7f847b4e9

Added to database: 07/30/2026, 15:50:47 UTC

Last enriched: 07/30/2026, 16:10:08 UTC

Last updated: 09/10/2026, 19:36:50 UTC

Views: 42

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses