
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-38496 is a vulnerability discovered in the Linux kernel's dm-bufio component, specifically related to scheduling in atomic context. The issue was disclosed on July 28, 2025, affecting systems where 'try_verify_in_tasklet' is set for dm-verity, causing DM_BUFIO_CLIENT_NO_SLEEP to be enabled for dm-bufio (NVD).
The vulnerability occurs when bufio attempts to evict buffers, potentially triggering scheduling in spin_lock_bh. This results in a sleeping function being called from an invalid context at drivers/md/dm-bufio.c:2745. The issue manifests with specific conditions: in_atomic(): 1, irqs_disabled(): 0, non_block: 0, and involves multiple locks held by the kworker process (NVD).
When exploited, this vulnerability can cause system instability by triggering kernel warnings and potentially affecting the dm-verity functionality, which is crucial for maintaining verified boot and system integrity (Debian Tracker).
The vulnerability can be reproduced using specific commands involving veritysetup format with data-block-size and hash-block-size parameters, followed by dmsetup create operations and mounting the affected device (NVD).
The vulnerability has been fixed in various Linux kernel versions. Debian has addressed this in bullseye (5.10.223-1) and bookworm (6.1.137-1) releases, while it remains vulnerable in trixie, forky, and sid distributions (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."