CVE-2025-38140
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-38140 is a vulnerability discovered in the Linux kernel related to device management (dm) and zone write plugs. The vulnerability was disclosed on July 3, 2025, affecting the Linux kernel's device mapper component. The issue specifically involves the dm_revalidate_zones() function's handling of zoned devices and their table reloads (CVE Mitre, NVD).

Technical details

The vulnerability occurs when dm_revalidate_zones() only allows new or previously unzoned devices to call blk_revalidate_disk_zones(). For already zoned devices, disk->nr_zones would always equal md->nr_zones, causing dm_revalidate_zones() to return without performing necessary updates. This can lead to mismatched zoned settings and potential invalid memory access through bdev_zone_is_seq() due to incorrectly sized disk->conv_zones_bitmap (Debian Tracker).

Impact

When exploited, this vulnerability can cause the zoned settings for the device to mismatch the new table. In devices with zone write plug resources, this can result in errors such as invalid memory access through bdev_zone_is_seq(). Additionally, if blk_revalidate_disk_zones() fails, it may incorrectly modify or clear the current disk->nr_zones value (CVE Mitre).

Mitigation and workarounds

The implemented solution disallows any table reloads that change the zoned settings for devices that already have zone plug resources. Specifically, devices with allocated zone plug resources can only switch to another zoned table that emulates zone append, without changing the device size or zone size. Devices can still switch to an error target as needed (CVE Mitre).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-68753HIGH7.8
  • Linux KernelLinux Kernel
  • linux-fips
NoYesJan 05, 2026
CVE-2025-68756HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-fips
NoYesJan 05, 2026
CVE-2025-68764MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-oracle-6.8
NoYesJan 05, 2026
CVE-2025-68758MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-nvidia-6.8
NoYesJan 05, 2026
CVE-2025-68762N/AN/A
  • Linux KernelLinux Kernel
  • kernel-devel
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management