eventpoll: Fix semi-unbounded recursion
Summary
| CVE | CVE-2025-38614 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-08-19 17:15:40 UTC |
| Updated | 2026-07-14 13:17:41 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: eventpoll: Fix semi-unbounded recursion Ensure that epoll instances can never form a graph deeper than EP_MAX_NESTS+1 links. Currently, ep_loop_check_proc() ensures that the graph is loop-free and does some recursion depth checks, but those recursion depth checks don't limit the depth of the resulting tree for two reasons: - They don't look upwards in the tree. - If there are multiple downwards paths of different lengths, only one of the paths is actually considered for the depth check since commit 28d82dc1c4ed ("epoll: limit paths"). Essentially, the current recursion depth check in ep_loop_check_proc() just serves to prevent it from recursing too deeply while checking for loops. A more thorough check is done in reverse_path_check() after the new graph edge has already been created; this checks, among other things, that no paths going upwards from any non-epoll file with a length of more than 5 edges exist. However, this check does not apply to non-epoll files. As a result, it is possible to recurse to a depth of at least roughly 500, tested on v6.15. (I am unsure if deeper recursion is possible; and this may have changed with commit 8c44dac8add7 ("eventpoll: Fix priority inversion problem").) To fix it: 1. In ep_loop_check_proc(), note the subtree depth of each visited node, and use subtree depths for the total depth calculation even when a subtree has already been visited. 2. Add ep_get_upwards_depth_proc() for similarly determining the maximum depth of an upwards walk. 3. In ep_loop_check(), use these values to limit the total path length between epoll nodes to EP_MAX_NESTS edges. |
Risk And Classification
Primary CVSS: v3.1 5.5 MEDIUM from [email protected]
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Problem Types: CWE-674
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e 71379495ab70eaba19224bd71b5b9b399eb85e04 git | Not specified |
| CNA | Linux | Linux | affected 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e 1b13b033062824495554e836a1ff5f85ccf6b039 git | Not specified |
| CNA | Linux | Linux | affected 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e 2a0c0c974bea9619c6f41794775ae4b97530e0e6 git | Not specified |
| CNA | Linux | Linux | affected 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e 7a2125962c42d5336ca0495a9ce4cb38a63e9161 git | Not specified |
| CNA | Linux | Linux | affected 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e ea5f97dbdcb1651581a22bd10afd2f0dd9dc11d6 git | Not specified |
| CNA | Linux | Linux | affected 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e 3542c90797bc3ab83ebab54b737d751cf3682036 git | Not specified |
| CNA | Linux | Linux | affected 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e f2e467a48287c868818085aa35389a224d226732 git | Not specified |
| CNA | Linux | Linux | affected 8216e1a0d47cae06a75c42346f19dffe14e42d57 git | Not specified |
| CNA | Linux | Linux | affected 28a92748aa4bc57d35e7b079498b0ac2e7610a37 git | Not specified |
| CNA | Linux | Linux | affected 7eebcd4792c5a341559aed327b6afecbb1c46402 git | Not specified |
| CNA | Linux | Linux | affected 0eccd188cfeaf857a26f2d72941d27d298cf6a54 git | Not specified |
| CNA | Linux | Linux | affected a72affdbb09f3f24f64ffcbbdf62c2e57c58f379 git | Not specified |
| CNA | Linux | Linux | affected 2.6.32.30 2.6.33 semver | Not specified |
| CNA | Linux | Linux | affected 2.6.33.8 2.6.34 semver | Not specified |
| CNA | Linux | Linux | affected 2.6.34.10 2.6.35 semver | Not specified |
| CNA | Linux | Linux | affected 2.6.35.12 2.6.36 semver | Not specified |
| CNA | Linux | Linux | affected 2.6.37.3 2.6.38 semver | Not specified |
| CNA | Linux | Linux | affected 2.6.38 | Not specified |
| CNA | Linux | Linux | unaffected 2.6.38 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.190 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.149 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.103 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.43 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.15.11 6.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.16.1 6.16.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.17 * original_commit_for_fix | Not specified |
| ADP | Siemens | SIMATIC CN 4100 | affected V5.0 custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
| ADP | Siemens | SIPLUS S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.5 * custom | Not specified |
| ADP | Siemens | SIPLUS S7-1500 CPU 1518-4 PN/DP MFP | affected V3.1.6 * custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/ea5f97dbdcb1651581a22bd10afd2f0dd9dc11d6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| lists.debian.org/debian-lts-announce/2025/10/msg00008.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | Third Party Advisory |
| cert-portal.siemens.com/productcert/html/ssa-082556.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| git.kernel.org/stable/c/7a2125962c42d5336ca0495a9ce4cb38a63e9161 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/71379495ab70eaba19224bd71b5b9b399eb85e04 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/1b13b033062824495554e836a1ff5f85ccf6b039 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/2a0c0c974bea9619c6f41794775ae4b97530e0e6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| cert-portal.siemens.com/productcert/html/ssa-019113.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| cert-portal.siemens.com/productcert/html/ssa-032379.html | 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e | cert-portal.siemens.com | |
| git.kernel.org/stable/c/f2e467a48287c868818085aa35389a224d226732 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| git.kernel.org/stable/c/3542c90797bc3ab83ebab54b737d751cf3682036 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.