CVE-2025-38498
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-38498 is a vulnerability discovered in the Linux kernel, specifically in the do_change_type() function, which was disclosed on July 30, 2025. The vulnerability affects the mount namespace functionality in the Linux kernel, where propagation settings could be changed for mounts outside the caller's mount namespace (NVD).

Technical details

The vulnerability exists in the do_change_type() function of the Linux kernel, which incorrectly allowed processes to modify mount propagation flags on mounts outside their own mount namespace. This issue has a CVSS v3.1 Base Score of 7.3 with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H, indicating a local attack vector with low attack complexity and requiring low privileges (Red Hat).

Impact

The vulnerability could enable a local attacker with mount privileges to disrupt or alter mount behavior in other namespaces, potentially causing system-wide denial of service. This breaks expected isolation guarantees between mount namespaces, which is a critical security boundary in containerized environments (Red Hat).

Mitigation and workarounds

The vulnerability has been resolved by ensuring that propagation settings can only be changed for mounts located in the caller's mount namespace, aligning permission checking with the rest of mount(2) functionality. Red Hat notes that alternative mitigation options are either not available or don't meet their Product Security criteria for ease of use, deployment, and stability (Red Hat).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-debug-devel
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • kernel-cross-headers
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-core
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-modules-core
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management