Answer in brief
CVE-2025-38614 records a Medium severity (CVSS 5.5) vulnerability in eventpoll: Fix semi-unbounded recursion. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC CN 4100 (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-38614 records a Medium severity (CVSS 5.5) vulnerability in eventpoll: Fix semi-unbounded recursion. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC CN 4100 (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC CN 4100 (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <71379495ab70eaba19224bd71b5b9b399eb85e04 || >=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <1b13b033062824495554e836a1ff5f85ccf6b039 || >=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <2a0c0c974bea9619c6f41794775ae4b97530e0e6 || >=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <7a2125962c42d5336ca0495a9ce4cb38a63e9161 || >=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <ea5f97dbdcb1651581a22bd10afd2f0dd9dc11d6 || >=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <3542c90797bc3ab83ebab54b737d751cf3682036 || >=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <f2e467a48287c868818085aa35389a224d226732 || 8216e1a0d47cae06a75c42346f19dffe14e42d57 || 28a92748aa4bc57d35e7b079498b0ac2e7610a37 || 7eebcd4792c5a341559aed327b6afecbb1c46402 || 0eccd188cfeaf857a26f2d72941d27d298cf6a54 || a72affdbb09f3f24f64ffcbbdf62c2e57c58f379 || >=2.6.32.30 <2.6.33 || >=2.6.33.8 <2.6.34 || >=2.6.34.10 <2.6.35 || >=2.6.35.12 <2.6.36 || >=2.6.37.3 <2.6.38 | 71379495ab70eaba19224bd71b5b9b399eb85e04, 1b13b033062824495554e836a1ff5f85ccf6b039, 2a0c0c974bea9619c6f41794775ae4b97530e0e6, 7a2125962c42d5336ca0495a9ce4cb38a63e9161, ea5f97dbdcb1651581a22bd10afd2f0dd9dc11d6, 3542c90797bc3ab83ebab54b737d751cf3682036, f2e467a48287c868818085aa35389a224d226732, 2.6.33, 2.6.34, 2.6.35, 2.6.36, 2.6.38 |
| Linux/Linuxgeneric | 2.6.38 | Not reported |
| Siemens/SIMATIC CN 4100generic | >=0 <V5.0 | V5.0 |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Published upstream
Aug 19, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 14, 2026
In the Linux kernel, the following vulnerability has been resolved: eventpoll: Fix semi-unbounded recursion Ensure that epoll instances can never form a graph deeper than EP_MAX_NESTS+1 links. Currently, ep_loop_check_proc() ensures that the graph is loop-free and does some recursion depth checks, but those recursion depth checks don't limit the depth of the resulting tree for two reasons: - They don't look upwards in the tree. - If there are multiple downwards paths of different lengths, only one of the paths is actually considered for the depth check since commit 28d82dc1c4ed ("epoll: limit paths"). Essentially, the current recursion depth check in ep_loop_check_proc() just serves to prevent it from recursing too deeply while checking for loops. A more thorough check is done in reverse_path_check() after the new graph edge has already been created; this checks, among other things, that no paths going upwards from any non-epoll file with a length of more than 5 edges exist. However, this check does not apply to non-epoll files. As a result, it is possible to recurse to a depth of at least roughly 500, tested on v6.15. (I am unsure if deeper recursion is possible; and this may have changed with commit 8c44dac8add7 ("eventpoll: Fix priority inversion problem").) To fix it: 1. In ep_loop_check_proc(), note the subtree depth of each visited node, and use subtree depths for the total depth calculation even when a subtree has already been visited. 2. Add ep_get_upwards_depth_proc() for similarly determining the maximum depth of an upwards walk. 3. In ep_loop_check(), use these values to limit the total path length between epoll nodes to EP_MAX_NESTS edges.
Quoted source text, attributed separately from HOL analysis.
CVSS is 5.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC CN 4100 (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <71379495ab70eaba19224bd71b5b9b399eb85e04 || >=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <1b13b033062824495554e836a1ff5f85ccf6b039 || >=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <2a0c0c974bea9619c6f41794775ae4b97530e0e6 || >=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <7a2125962c42d5336ca0495a9ce4cb38a63e9161 || >=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <ea5f97dbdcb1651581a22bd10afd2f0dd9dc11d6 || >=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <3542c90797bc3ab83ebab54b737d751cf3682036 || >=22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <f2e467a48287c868818085aa35389a224d226732 || 8216e1a0d47cae06a75c42346f19dffe14e42d57 || 28a92748aa4bc57d35e7b079498b0ac2e7610a37 || 7eebcd4792c5a341559aed327b6afecbb1c46402 || 0eccd188cfeaf857a26f2d72941d27d298cf6a54 || a72affdbb09f3f24f64ffcbbdf62c2e57c58f379 || >=2.6.32.30 <2.6.33 || >=2.6.33.8 <2.6.34 || >=2.6.34.10 <2.6.35 || >=2.6.35.12 <2.6.36 || >=2.6.37.3 <2.6.38 | 71379495ab70eaba19224bd71b5b9b399eb85e04, 1b13b033062824495554e836a1ff5f85ccf6b039, 2a0c0c974bea9619c6f41794775ae4b97530e0e6, 7a2125962c42d5336ca0495a9ce4cb38a63e9161, ea5f97dbdcb1651581a22bd10afd2f0dd9dc11d6, 3542c90797bc3ab83ebab54b737d751cf3682036, f2e467a48287c868818085aa35389a224d226732, 2.6.33, 2.6.34, 2.6.35, 2.6.36, 2.6.38 |
| Linux/Linuxgeneric | 2.6.38 | Not reported |
| Siemens/SIMATIC CN 4100generic | >=0 <V5.0 | V5.0 |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Published upstream
Aug 19, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 14, 2026
In the Linux kernel, the following vulnerability has been resolved: eventpoll: Fix semi-unbounded recursion Ensure that epoll instances can never form a graph deeper than EP_MAX_NESTS+1 links. Currently, ep_loop_check_proc() ensures that the graph is loop-free and does some recursion depth checks, but those recursion depth checks don't limit the depth of the resulting tree for two reasons: - They don't look upwards in the tree. - If there are multiple downwards paths of different lengths, only one of the paths is actually considered for the depth check since commit 28d82dc1c4ed ("epoll: limit paths"). Essentially, the current recursion depth check in ep_loop_check_proc() just serves to prevent it from recursing too deeply while checking for loops. A more thorough check is done in reverse_path_check() after the new graph edge has already been created; this checks, among other things, that no paths going upwards from any non-epoll file with a length of more than 5 edges exist. However, this check does not apply to non-epoll files. As a result, it is possible to recurse to a depth of at least roughly 500, tested on v6.15. (I am unsure if deeper recursion is possible; and this may have changed with commit 8c44dac8add7 ("eventpoll: Fix priority inversion problem").) To fix it: 1. In ep_loop_check_proc(), note the subtree depth of each visited node, and use subtree depths for the total depth calculation even when a subtree has already been visited. 2. Add ep_get_upwards_depth_proc() for similarly determining the maximum depth of an upwards walk. 3. In ep_loop_check(), use these values to limit the total path length between epoll nodes to EP_MAX_NESTS edges.
Quoted source text, attributed separately from HOL analysis.