{"id":"DEBIAN-CVE-2025-38525","details":"In the Linux kernel, the following vulnerability has been resolved:  rxrpc: Fix irq-disabled in local_bh_enable()  The rxrpc_assess_MTU_size() function calls down into the IP layer to find out the MTU size for a route.  When accepting an incoming call, this is called from rxrpc_new_incoming_call() which holds interrupts disabled across the code that calls down to it.  Unfortunately, the IP layer uses local_bh_enable() which, config dependent, throws a warning if IRQs are enabled:  WARNING: CPU: 1 PID: 5544 at kernel/softirq.c:387 __local_bh_enable_ip+0x43/0xd0 ... RIP: 0010:__local_bh_enable_ip+0x43/0xd0 ... Call Trace:  \u003cTASK\u003e  rt_cache_route+0x7e/0xa0  rt_set_nexthop.isra.0+0x3b3/0x3f0  __mkroute_output+0x43a/0x460  ip_route_output_key_hash+0xf7/0x140  ip_route_output_flow+0x1b/0x90  rxrpc_assess_MTU_size.isra.0+0x2a0/0x590  rxrpc_new_incoming_peer+0x46/0x120  rxrpc_alloc_incoming_call+0x1b1/0x400  rxrpc_new_incoming_call+0x1da/0x5e0  rxrpc_input_packet+0x827/0x900  rxrpc_io_thread+0x403/0xb60  kthread+0x2f7/0x310  ret_from_fork+0x2a/0x230  ret_from_fork_asm+0x1a/0x30 ... hardirqs last  enabled at (23): _raw_spin_unlock_irq+0x24/0x50 hardirqs last disabled at (24): _raw_read_lock_irq+0x17/0x70 softirqs last  enabled at (0): copy_process+0xc61/0x2730 softirqs last disabled at (25): rt_add_uncached_list+0x3c/0x90  Fix this by moving the call to rxrpc_assess_MTU_size() out of rxrpc_init_peer() and further up the stack where it can be done without interrupts disabled.  It shouldn't be a problem for rxrpc_new_incoming_call() to do it after the locks are dropped as pmtud is going to be performed by the I/O thread - and we're in the I/O thread at this point.","modified":"2026-09-19T22:00:29.250060070Z","published":"2025-08-16T12:15:27.933Z","upstream":["CVE-2025-38525"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38525"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.105-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38525.json"}},{"package":{"name":"linux-6.12","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux-6.12?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.107-1~deb12u1"}]}],"versions":["6.12.100-1~deb12u1","6.12.101-1~deb12u1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38525.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}