{"id":"CVE-2025-40348","summary":"slab: Avoid race on slab-\u003eobj_exts in alloc_slab_obj_exts","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nslab: Avoid race on slab-\u003eobj_exts in alloc_slab_obj_exts\n\nIf two competing threads enter alloc_slab_obj_exts() and one of them\nfails to allocate the object extension vector, it might override the\nvalid slab-\u003eobj_exts allocated by the other thread with\nOBJEXTS_ALLOC_FAIL. This will cause the thread that lost this race and\nexpects a valid pointer to dereference a NULL pointer later on.\n\nUpdate slab-\u003eobj_exts atomically using cmpxchg() to avoid\nslab-\u003eobj_exts overrides by racing threads.\n\nThanks for Vlastimil and Suren's help with debugging.","modified":"2026-08-12T03:51:27.844650463Z","published":"2025-12-16T13:30:22.368Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40348.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/6ed8bfd24ce1cb31742b09a3eb557cd008533eec"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7c34feda6a9a203c9744281f1b6671b7dad2012d"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c7af5300d78460fc5037ddc77113ba3dbfe77dc0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/40xxx/CVE-2025-40348.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-40348"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"715b6a5b41dae39baeaa40d3386b548bb278b9c2"},{"fixed":"c7af5300d78460fc5037ddc77113ba3dbfe77dc0"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"07e38a54cabd9b4de7ceb7f075f29ffa463e458a"},{"fixed":"7c34feda6a9a203c9744281f1b6671b7dad2012d"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"f7381b9116407ba2a429977c80ff8df953ea9354"},{"fixed":"6ed8bfd24ce1cb31742b09a3eb557cd008533eec"}]}],"versions":["v6.12.55","v6.12.54","v6.17.5","v6.17.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40348.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.12.54"},{"fixed":"6.12.56"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.17.4"},{"fixed":"6.17.6"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-40348.json"}}],"schema_version":"1.9.0"}