In the Linux kernel, the following vulnerability has been resolved: padata: Fix pd UAF once and for all There is a race condition/UAF in… (CVE-2025-38584)
In the Linux kernel, the following vulnerability has been resolved: padata: Fix pd UAF once and for all There is a race condition/UAF in padata_reorder that goes back to the initial commit. A reference count is taken at the start of the process in padata_do_parallel, and released at the end in padata_serial_worker. This reference count is (and only is) required for padata_replace to function correctly. If padata_replace is never called then there is no issue. In the function padata_reorder which serves as the core of padata, as soon as padata is added to queue->serial.list, and the associated spin lock released, that padata may be processed and the reference count on pd would go away. Fix this by getting the next padata before the squeue->serial lock is released. In order to make this possible, simplify padata_reorder by only calling it once the next padata arrives.
AI Analysis
Technical Summary
This vulnerability, tracked as CVE-2025-38584, involves a use-after-free (UAF) flaw in the 'padata' component of Microsoft software versions 2.0 and 3.0. The description and technical details are minimal, with no CVSS score or exploitation details provided. The vendor advisory does not specify patch availability or mitigation steps. The vulnerability was published on August 2, 2025, by the Microsoft Security Response Center.
Potential Impact
The impact details are not explicitly described in the provided information. Use-after-free vulnerabilities typically can lead to memory corruption, potentially allowing an attacker to execute arbitrary code or cause denial of service. However, without specific details or known exploits, the exact impact remains unclear.
Mitigation Recommendations
Patch status is not yet confirmed — check the Microsoft Security Response Center advisory for current remediation guidance. No official fix or workaround information is provided in the available data.
In the Linux kernel, the following vulnerability has been resolved: padata: Fix pd UAF once and for all There is a race condition/UAF in… (CVE-2025-38584)
Description
In the Linux kernel, the following vulnerability has been resolved: padata: Fix pd UAF once and for all There is a race condition/UAF in padata_reorder that goes back to the initial commit. A reference count is taken at the start of the process in padata_do_parallel, and released at the end in padata_serial_worker. This reference count is (and only is) required for padata_replace to function correctly. If padata_replace is never called then there is no issue. In the function padata_reorder which serves as the core of padata, as soon as padata is added to queue->serial.list, and the associated spin lock released, that padata may be processed and the reference count on pd would go away. Fix this by getting the next padata before the squeue->serial lock is released. In order to make this possible, simplify padata_reorder by only calling it once the next padata arrives.
CVSS v3.1
Score 7.8high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability, tracked as CVE-2025-38584, involves a use-after-free (UAF) flaw in the 'padata' component of Microsoft software versions 2.0 and 3.0. The description and technical details are minimal, with no CVSS score or exploitation details provided. The vendor advisory does not specify patch availability or mitigation steps. The vulnerability was published on August 2, 2025, by the Microsoft Security Response Center.
Potential Impact
The impact details are not explicitly described in the provided information. Use-after-free vulnerabilities typically can lead to memory corruption, potentially allowing an attacker to execute arbitrary code or cause denial of service. However, without specific details or known exploits, the exact impact remains unclear.
Mitigation Recommendations
Patch status is not yet confirmed — check the Microsoft Security Response Center advisory for current remediation guidance. No official fix or workaround information is provided in the available data.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_vex
- Csaf Version
- 2.0
- Publisher
- Microsoft Security Response Center
- Advisory Id
- msrc_CVE-2025-38584
- Cve Count
- 1
Threat ID: 6a3c0d26eed863c81e23ef41
Added to database: 06/24/2026, 17:00:22 UTC
Last enriched: 06/24/2026, 17:21:48 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 44
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.