Answer in brief
CVE-2025-38396 records a Unknown severity vulnerability in fs: export anon_inode_make_secure_inode() and fix secretmem LSM bypass. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | 6.0 | Not reported |
| Linux/Linuxgeneric | >=2bfe15c5261212130f1a71f32a300bcf426443d4 <66d29d757c968d2bee9124816da5d718eb352959 || >=2bfe15c5261212130f1a71f32a300bcf426443d4 <e3eed01347721cd7a8819568161c91d538fbf229 || >=2bfe15c5261212130f1a71f32a300bcf426443d4 <f94c422157f3e43dd31990567b3e5d54b3e5b32b || >=2bfe15c5261212130f1a71f32a300bcf426443d4 <6ca45ea48530332a4ba09595767bd26d3232743b || >=2bfe15c5261212130f1a71f32a300bcf426443d4 <cbe4134ea4bc493239786220bd69cb8a13493190 | 66d29d757c968d2bee9124816da5d718eb352959, e3eed01347721cd7a8819568161c91d538fbf229, f94c422157f3e43dd31990567b3e5d54b3e5b32b, 6ca45ea48530332a4ba09595767bd26d3232743b, cbe4134ea4bc493239786220bd69cb8a13493190 |
Published upstream
Jul 25, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: fs: export anon_inode_make_secure_inode() and fix secretmem LSM bypass Export anon_inode_make_secure_inode() to allow KVM guest_memfd to create anonymous inodes with proper security context. This replaces the current pattern of calling alloc_anon_inode() followed by inode_init_security_anon() for creating security context manually. This change also fixes a security regression in secretmem where the S_PRIVATE flag was not cleared after alloc_anon_inode(), causing LSM/SELinux checks to be bypassed for secretmem file descriptors. As guest_memfd currently resides in the KVM module, we need to export this symbol for use outside the core kernel. In the future, guest_memfd might be moved to core-mm, at which point the symbols no longer would have to be exported. When/if that happens is still unclear.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-38396 records a Unknown severity vulnerability in fs: export anon_inode_make_secure_inode() and fix secretmem LSM bypass. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | 6.0 | Not reported |
| Linux/Linuxgeneric | >=2bfe15c5261212130f1a71f32a300bcf426443d4 <66d29d757c968d2bee9124816da5d718eb352959 || >=2bfe15c5261212130f1a71f32a300bcf426443d4 <e3eed01347721cd7a8819568161c91d538fbf229 || >=2bfe15c5261212130f1a71f32a300bcf426443d4 <f94c422157f3e43dd31990567b3e5d54b3e5b32b || >=2bfe15c5261212130f1a71f32a300bcf426443d4 <6ca45ea48530332a4ba09595767bd26d3232743b || >=2bfe15c5261212130f1a71f32a300bcf426443d4 <cbe4134ea4bc493239786220bd69cb8a13493190 | 66d29d757c968d2bee9124816da5d718eb352959, e3eed01347721cd7a8819568161c91d538fbf229, f94c422157f3e43dd31990567b3e5d54b3e5b32b, 6ca45ea48530332a4ba09595767bd26d3232743b, cbe4134ea4bc493239786220bd69cb8a13493190 |
Published upstream
Jul 25, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: fs: export anon_inode_make_secure_inode() and fix secretmem LSM bypass Export anon_inode_make_secure_inode() to allow KVM guest_memfd to create anonymous inodes with proper security context. This replaces the current pattern of calling alloc_anon_inode() followed by inode_init_security_anon() for creating security context manually. This change also fixes a security regression in secretmem where the S_PRIVATE flag was not cleared after alloc_anon_inode(), causing LSM/SELinux checks to be bypassed for secretmem file descriptors. As guest_memfd currently resides in the KVM module, we need to export this symbol for use outside the core kernel. In the future, guest_memfd might be moved to core-mm, at which point the symbols no longer would have to be exported. When/if that happens is still unclear.
Quoted source text, attributed separately from HOL analysis.