{"id":"DEBIAN-CVE-2025-38727","details":"In the Linux kernel, the following vulnerability has been resolved:  netlink: avoid infinite retry looping in netlink_unicast()  netlink_attachskb() checks for the socket's read memory allocation constraints. Firstly, it has:    rmem \u003c READ_ONCE(sk-\u003esk_rcvbuf)  to check if the just increased rmem value fits into the socket's receive buffer. If not, it proceeds and tries to wait for the memory under:    rmem + skb-\u003etruesize \u003e READ_ONCE(sk-\u003esk_rcvbuf)  The checks don't cover the case when skb-\u003etruesize + sk-\u003esk_rmem_alloc is equal to sk-\u003esk_rcvbuf. Thus the function neither successfully accepts these conditions, nor manages to reschedule the task - and is called in retry loop for indefinite time which is caught as:    rcu: INFO: rcu_sched self-detected stall on CPU   rcu:     0-....: (25999 ticks this GP) idle=ef2/1/0x4000000000000000 softirq=262269/262269 fqs=6212   (t=26000 jiffies g=230833 q=259957)   NMI backtrace for cpu 0   CPU: 0 PID: 22 Comm: kauditd Not tainted 5.10.240 #68   Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc42 04/01/2014   Call Trace:   \u003cIRQ\u003e   dump_stack lib/dump_stack.c:120   nmi_cpu_backtrace.cold lib/nmi_backtrace.c:105   nmi_trigger_cpumask_backtrace lib/nmi_backtrace.c:62   rcu_dump_cpu_stacks kernel/rcu/tree_stall.h:335   rcu_sched_clock_irq.cold kernel/rcu/tree.c:2590   update_process_times kernel/time/timer.c:1953   tick_sched_handle kernel/time/tick-sched.c:227   tick_sched_timer kernel/time/tick-sched.c:1399   __hrtimer_run_queues kernel/time/hrtimer.c:1652   hrtimer_interrupt kernel/time/hrtimer.c:1717   __sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1113   asm_call_irq_on_stack arch/x86/entry/entry_64.S:808   \u003c/IRQ\u003e    netlink_attachskb net/netlink/af_netlink.c:1234   netlink_unicast net/netlink/af_netlink.c:1349   kauditd_send_queue kernel/audit.c:776   kauditd_thread kernel/audit.c:897   kthread kernel/kthread.c:328   ret_from_fork arch/x86/entry/entry_64.S:304  Restore the original behavior of the check which commit in Fixes accidentally missed when restructuring the code.  Found by Linux Verification Center (linuxtesting.org).","modified":"2026-09-01T16:06:15.355795687Z","published":"2025-09-04T16:15:42.713Z","upstream":["CVE-2025-38727"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38727"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.153-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.140-1","6.1.147-1","6.1.148-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38727.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.43-1"}]}],"versions":["6.12.38-1","6.12.41-1","6.12.43-1~bpo12+1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38727.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.16.3-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.107-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.3-1~bpo13+1","6.16~rc7-1~exp1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38727.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}