CVE-2025-38129: page_pool: Fix use-after-free in page_pool_recycle_in_ring
In the Linux kernel, the following vulnerability has been resolved:
page_pool: Fix use-after-free in page_pool_recycle_in_ring
syzbot reported a uaf in page_pool_recycle_in_ring:
BUG: KASAN: slab-use-after-free in lock_release+0x151/0xa30 kernel/locking/lockdep.c:5862
Read of size 8 at addr ffff8880286045a0 by task syz.0.284/6943
CPU: 0 UID: 0 PID: 6943 Comm: syz.0.284 Not tainted 6.13.0-rc3-syzkaller-gdfa94ce54f41 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
Call Trace:
<TASK>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0x169/0x550 mm/kasan/report.c:489
kasan_report+0x143/0x180 mm/kasan/report.c:602
lock_release+0x151/0xa30 kernel/locking/lockdep.c:5862
__raw_spin_unlock_bh include/linux/spinlock_api_smp.h:165 [inline]
_raw_spin_unlock_bh+0x1b/0x40 kernel/locking/spinlock.c:210
spin_unlock_bh include/linux/spinlock.h:396 [inline]
ptr_ring_produce_bh include/linux/ptr_ring.h:164 [inline]
page_pool_recycle_in_ring net/core/page_pool.c:707 [inline]
page_pool_put_unrefed_netmem+0x748/0xb00 net/core/page_pool.c:826
page_pool_put_netmem include/net/page_pool/helpers.h:323 [inline]
page_pool_put_full_netmem include/net/page_pool/helpers.h:353 [inline]
napi_pp_put_page+0x149/0x2b0 net/core/skbuff.c:1036
skb_pp_recycle net/core/skbuff.c:1047 [inline]
skb_free_head net/core/skbuff.c:1094 [inline]
skb_release_data+0x6c4/0x8a0 net/core/skbuff.c:1125
skb_release_all net/core/skbuff.c:1190 [inline]
__kfree_skb net/core/skbuff.c:1204 [inline]
sk_skb_reason_drop+0x1c9/0x380 net/core/skbuff.c:1242
kfree_skb_reason include/linux/skbuff.h:1263 [inline]
__skb_queue_purge_reason include/linux/skbuff.h:3343 [inline]
root cause is:
page_pool_recycle_in_ring
ptr_ring_produce
spin_lock(&r->producer_lock);
WRITE_ONCE(r->queue[r->producer++], ptr)
//recycle last page to pool
page_pool_release
page_pool_scrub
page_pool_empty_ring
ptr_ring_consume
page_pool_return_page //release all page
__page_pool_destroy
free_percpu(pool->recycle_stats);
free(pool) //free
spin_unlock(&r->producer_lock); //pool->ring uaf read
recycle_stat_inc(pool, ring);
page_pool can be free while page pool recycle the last page in ring.
Add producer-lock barrier to page_pool_release to prevent the page
pool from being free before all pages have been recycled.
recycle_stat_inc() is empty when CONFIG_PAGE_POOL_STATS is not
enabled, which will trigger Wempty-body build warning. Add definition
for pool stat macro to fix warning.
Security readout for executives and security teams
Plain-English summary
CVE-2025-38129 is a Linux kernel memory-safety flaw in network page recycling. A local, low-privileged attacker may be able to trigger use-after-free behavior, potentially compromising confidentiality, integrity, or availability. The supplied CVSS score is 7.8, but the evidence does not establish a reliable privilege-escalation path.
Executive priority
Prioritize normal high-severity remediation, accelerating internet-facing infrastructure, shared hosts, and systems with untrusted local users. This is not supported as an emergency active-exploitation event, but kernel memory corruption warrants timely patching because successful abuse could affect the entire host.
Technical view
A race allows a page_pool object to be freed while page_pool_recycle_in_ring still accesses its ring lock and statistics. The kernel fix adds a producer-lock barrier during page_pool_release, preventing destruction before recycling completes. The supplied report demonstrates the use-after-free with KASAN and syzbot, not successful exploitation.
Likely exposure
Exposure is limited to Linux systems running affected kernels where the networking page_pool path can be reached. The supplied version data lists several affected releases but is ambiguous and includes commit identifiers without clear ranges. Confirm exposure using distribution advisories and exact kernel build provenance.
Exploitation context
The supplied CVSS vector requires local access, low privileges, and no user interaction. CISA KEV status is false in the bundle, and no cited source establishes active exploitation or a public working exploit. Treat impact claims beyond the demonstrated kernel use-after-free as potential, not confirmed.
Researcher notes
The demonstrated failure occurs when page_pool_release empties and destroys the pool while a producer still holds or later releases pool->ring.producer_lock. Validation should focus on fix presence and reachability of page_pool-backed networking. The supplied sources do not identify affected drivers, exploitation primitives, or confirmed real-world attacks.
Mitigation direction
Update to a vendor-supported kernel containing the applicable page_pool fix.
Match the running kernel build against distribution security advisories and listed stable commits.
Prioritize multi-user, container-hosting, and other systems granting untrusted local access.
Restrict unnecessary local access until affected systems are patched.
Validation and detection
Record each system's exact running kernel release and distribution package version.
Verify the vendor package includes the producer-lock barrier fix or corresponding stable commit.
Confirm systems rebooted into the corrected kernel after installation.
Monitor kernel logs for KASAN, page_pool, use-after-free, or unexplained network-related crashes.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-38129 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
8Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: noTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.