🛡️ UBUNTU-CVE-2025-23138
⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

In the Linux kernel, the following vulnerability has been resolved: watch_queue: fix pipe accounting mismatch Currently, watch_queue_set_size() modifies the pipe buffers charged to user->pipe_bufs without updating the pipe->nr_accounted on the pipe itself, due to the if (!pipe_has_watch_queue()) test in pipe_resize_ring(). This means that when the pipe is ultimately freed, we decrement user->pipe_bufs by something other than what than we had charged to it, potentially leading to an underflow. This in turn can cause subsequent too_many_pipe_buffers_soft() tests to fail with -EPERM. To remedy this, explicitly account for the pipe usage in watch_queue_set_size() to match the number set via account_pipe_buffers() (It's unclear why watch_queue_set_size() does not update nr_accounted; it may be due to intentional overprovisioning in watch_queue_set_size()?)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-04-16
Updated 2026-06-15
Modified 2026-06-08
Fix URL N/A

Affected Packages

Software From version Fixed in
linux 6.8.0-86.87
linux-allwinner-5.19
linux-aws 6.8.0-1041.43
linux-aws-5.0
linux-aws-5.11
linux-aws-5.13
linux-aws-5.15 5.15.0-1086.93~20.04.1
linux-aws-5.19
linux-aws-5.3
linux-aws-5.8
linux-aws-6.2
linux-aws-6.5
linux-aws-6.8 6.8.0-1041.43~22.04.1
linux-aws-fips 6.8.0-1041.43+fips1
linux-azure 6.8.0-1041.47
linux-azure-5.11
linux-azure-5.13
linux-azure-5.15 5.15.0-1091.100~20.04.1
linux-azure-5.19
linux-azure-5.3
linux-azure-5.8
linux-azure-6.11 6.11.0-1018.18~24.04.1
linux-azure-6.2
linux-azure-6.5
linux-azure-6.8 6.8.0-1041.47~22.04.1
linux-azure-edge
linux-azure-fde
linux-azure-fde-5.19
linux-azure-fde-6.17
linux-azure-fde-6.2
linux-azure-fips 6.8.0-1044.50+fips1
linux-azure-nvidia 6.8.0-1029.32
linux-bluefield
linux-fips 6.8.0-86.87+fips1
linux-gcp 6.8.0-1042.45
linux-gcp-5.11
linux-gcp-5.13
linux-gcp-5.15 5.15.0-1085.94~20.04.1
linux-gcp-5.19
linux-gcp-5.3
linux-gcp-5.8
linux-gcp-6.11 6.11.0-1016.16~24.04.1
linux-gcp-6.2
linux-gcp-6.5
linux-gcp-6.8 6.8.0-1042.45~22.04.1
linux-gcp-fips 6.8.0-1042.45+fips1
linux-gke 6.8.0-1038.43
linux-gke-4.15
linux-gke-5.15
linux-gke-5.4
linux-gkeop 6.8.0-1025.28
linux-gkeop-5.15
linux-gkeop-5.4
linux-hwe
linux-hwe-5.11
linux-hwe-5.13
linux-hwe-5.15 5.15.0-142.152~20.04.1
linux-hwe-5.19
linux-hwe-5.8
linux-hwe-6.11 6.11.0-28.28~24.04.1
linux-hwe-6.2
linux-hwe-6.5
linux-hwe-6.8 6.8.0-86.87~22.04.1
linux-hwe-edge
linux-ibm 6.8.0-1039.39
linux-ibm-5.15 5.15.0-1078.81~20.04.1
linux-ibm-6.8 6.8.0-1039.39~22.04.1
linux-intel
linux-intel-5.13
linux-intel-iot-realtime 5.15.0-1079.81
linux-intel-iotg 5.15.0-1081.87
linux-intel-iotg-5.15 5.15.0-1083.89~20.04.1
linux-kvm 5.15.0-1082.87
linux-lowlatency 6.8.0-86.87.1
linux-lowlatency-hwe-5.15 5.15.0-142.152~20.04.1
linux-lowlatency-hwe-5.19
linux-lowlatency-hwe-6.11 6.11.0-1015.16~24.04.2
linux-lowlatency-hwe-6.2
linux-lowlatency-hwe-6.5
linux-lowlatency-hwe-6.8 6.8.0-86.87.1~22.04.1
linux-nvidia 6.8.0-1041.44
linux-nvidia-6.11 6.11.0-1012.12
linux-nvidia-6.2
linux-nvidia-6.5
linux-nvidia-6.8 6.8.0-1041.44~22.04.2
linux-nvidia-lowlatency 6.8.0-1041.44.1
linux-nvidia-tegra 6.8.0-1012.12
linux-nvidia-tegra-5.15 5.15.0-1039.39~20.04.1
linux-nvidia-tegra-igx 5.15.0-1028.28
linux-oem
linux-oem-5.10
linux-oem-5.13
linux-oem-5.14
linux-oem-5.17
linux-oem-5.6
linux-oem-6.0
linux-oem-6.1
linux-oem-6.11 6.11.0-1024.24
linux-oem-6.5
linux-oem-6.8
linux-oracle 6.8.0-1038.39
linux-oracle-5.0
linux-oracle-5.11
linux-oracle-5.13
linux-oracle-5.15 5.15.0-1083.89~20.04.1
linux-oracle-5.3
linux-oracle-5.8
linux-oracle-6.5
linux-oracle-6.8 6.8.0-1038.39~22.04.1
linux-raspi 6.8.0-1041.45
linux-raspi-realtime 6.8.0-2032.33
linux-raspi2
linux-realtime 6.8.1-1036.37
linux-realtime-6.8 6.8.1-1036.37~22.04.1
linux-riscv
linux-riscv-5.11
linux-riscv-5.15 5.15.0-1081.85~20.04.1
linux-riscv-5.19
linux-riscv-5.8
linux-riscv-6.5
linux-riscv-6.8 6.8.0-86.87~22.04.1
linux-starfive-5.19
linux-starfive-6.2
linux-starfive-6.5
linux-xilinx 6.8.0-1018.19
linux-xilinx-zynqmp 5.15.0-1050.54

References

Similar Threats

Free Vulnerability Check

Is your WordPress site affected?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.