CVE-2025-38396: fs: export anon_inode_make_secure_inode() and fix secretmem LSM bypass

Published Jul 25, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

fs: export anoninodemakesecureinode() and fix secretmem LSM bypass

Export anoninodemakesecureinode() to allow KVM guestmemfd to create anonymous inodes with proper security context. This replaces the current pattern of calling allocanoninode() followed by inodeinitsecurityanon() for creating security context manually.

This change also fixes a security regression in secretmem where the SPRIVATE flag was not cleared after allocanoninode(), causing LSM/SELinux checks to be bypassed for secretmem file descriptors.

As guestmemfd currently resides in the KVM module, we need to export this symbol for use outside the core kernel. In the future, guestmemfd might be moved to core-mm, at which point the symbols no longer would have to be exported. When/if that happens is still unclear.

Affected Software

14 affected components
Linux Linux kernel
Linux Linux kernel>=6.0<6.1.146
Linux Linux kernel>=6.2<6.6.97
Linux Linux kernel>=6.7<6.12.37
Linux Linux kernel>=6.13<6.15.6
Linux Linux kernel=6.16-rc1
Linux Linux kernel=6.16-rc2
Linux Linux kernel=6.16-rc3
Linux Linux kernel=6.16-rc4
Debian Debian Linux=11.0
IBM Verify Identity Access<=11.0 - 11.0.2
IBM Security Verify Access<=10.0 - 10.0.9.1
IBM Verify Identity Access Container<=11.0 - 11.0.2
IBM Security Verify Access Container<=10.0 - 10.0.9.1

Event History

Jul 25, 2025
CVE Published
via MITRE·12:53 PM
Data Sourced
via MITRE·12:53 PM
Description
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Red Hat·02:04 PM
DescriptionSeverityAffected Software
Jul 8, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-38396?

CVE-2025-38396 has a severity rating that indicates a potential security risk in the Linux kernel related to improper handling of anonymous inodes.

2

How do I fix CVE-2025-38396?

To fix CVE-2025-38396, update your Linux kernel to the latest version where the vulnerability has been patched.

3

What is the impact of CVE-2025-38396 on system security?

CVE-2025-38396 could allow for a security context bypass, potentially compromising the isolation of KVM guest memory.

4

Which versions of the Linux kernel are affected by CVE-2025-38396?

CVE-2025-38396 affects certain versions of the Linux kernel prior to the implementation of the fix.

5

Is there a public exploit available for CVE-2025-38396?

As of now, there are no known public exploits specifically targeting CVE-2025-38396.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203