CVE-2025-38617Exploit(debian / debian_linux)

CRITICALCVSS 4.7 · MEDIUM

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch debian debian_linux systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In the Linux kernel, the following vulnerability has been resolved: net/packet: fix a race in packet_set_ring() and packet_notifier() When packet_set_ring() releases po->bind_lock, another thread can run packet_notifier() and process an NETDEV_UP event. This race and the fix are both similar to that of commit 15fe076edea7 ("net/packet: fix a race in packet_bind() and packet_notifier()"). There too the packet_notifier NETDEV_UP event managed to run while a po->bind_lock critical section had to be temporarily released. And the fix was similarly to temporarily set po->num to zero to keep the socket unhooked until the lock is retaken. The po->bind_lock in packet_set_ring and packet_notifier precede the introduction of git history.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • linux_kernel

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 21 mentions across 15 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 10 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 13 signals
  • General: 6 classified signals
  • Peaked 6d ago at 3 mentions (2026-03-17); latest day: 1
  • 21 total mentions across 15 days

Affected systems

Products
debian_linuxlinux_kernel

2 versions affected across 2 products

Deep dive

Activity timeline21 mentions / 15d
01223Mentions · 2026-03-03: 1Mentions · 2026-03-04: 2Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 2Mentions · 2026-03-09: 1Mentions · 2026-03-10: 2Mentions · 2026-03-12: 1Mentions · 2026-03-17: 3Mentions · 2026-03-21: 1Mentions · 2026-03-26: 1Mentions · 2026-04-06: 1Mentions · 2026-04-12: 1Mentions · 2026-05-22: 2Mentions · 2026-07-10: 1PoC Mentioned / Linked · 2026-03-03: 1PoC Mentioned / Linked · 2026-03-04: 1PoC Mentioned / Linked · 2026-03-07: 2PoC Mentioned / Linked · 2026-03-09: 1PoC Mentioned / Linked · 2026-03-17: 2PoC Mentioned / Linked · 2026-03-26: 1PoC Mentioned / Linked · 2026-04-12: 1PoC Mentioned / Linked · 2026-05-22: 1Exploit Tool / Code · 2026-03-26: 1Exploit Tool / Code · 2026-05-22: 1Active Exploitation · 2026-07-10: 1Patch / Workaround · 2026-03-12: 1Patch / Workaround · 2026-05-22: 2Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 2Technical Details · 2026-03-06: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-17: 3Technical Details · 2026-04-12: 1Technical Details · 2026-05-22: 2Technical Details · 2026-07-10: 103-0303-0403-0503-0603-0703-0903-1003-1203-1703-2103-2604-0604-1205-2207-10
Signal classification6 categories
Exploit
733.3%
General
628.6%
PoC
419.0%
Disclosure
29.5%
Patch
14.8%
Active Exploitation
14.8%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-031
Exploit1
2026-03-042
Exploit1General1
2026-03-051
General1
2026-03-061
General1
2026-03-072
PoC2
2026-03-091
Exploit1
2026-03-102
General2
2026-03-121
Disclosure1
2026-03-173
Disclosure1General1PoC1
2026-03-211
Exploit1
2026-03-261
PoC1
2026-04-061
Exploit1
2026-04-121
Exploit1
2026-05-222
Exploit1Patch1
2026-07-101
Active Exploitation1
Full discourse20 posts
  • Calif@calif_io
    Exploit

    A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets. A step-by-step guide to exploiting a 20-year-old bug in the Linux kernel to achieve full privilege escalation and container escape, plus a cool bug-hunting heuristic. https://open.substack.com/pub/calif/p/a-race-within-a-race-exploiting-cve

    Post summary

    The post announces a step‑by‑step guide to exploiting CVE‑2025‑38617 for privilege escalation and container escape, offering a PoC and a heuristic for bug hunting.

    34811559711.1K
    1.3K followersView on X
  • 0xor0ne@0xor0ne
    Exploit

    Exploiting a use-after-free vulnerability in the Linux kernel’s packet socket subsystem, caused by a race condition between packet_set_ring() and packet_notifier() (CVE-2025-38617) https://blog.calif.io/p/a-race-within-a-race-exploiting-cve #infosec https://t.co/i8re1JTtT2

    Post summary

    The tweet references a use‑after‑free vulnerability (CVE‑2025‑38617) in the Linux kernel packet subsystem, points to a blog that likely contains a PoC, but offers no patch, active‑wild evidence or explicit exploit code.

    1290142697.8K
    91.4K followersView on X
  • Linux Kernel Security@linkersec
    PoC

    A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets Excellent article by Quang Le about exploiting CVE-2025-38617 — a race condition that leads to a use-after-free in the packet sockets implementation. https://blog.calif.io/p/a-race-within-a-race-exploiting-cve https://t.co/uRXwbhCRDf

    Post summary

    The tweet links to a blog post that showcases a proof‑of‑concept for CVE‑2025‑38617, a race‑condition use‑after‑free in Linux packet sockets, without mentioning active exploitation or patching.

    2230114636.1K
    9.9K followersView on X
  • 0xor0ne@0xor0ne
    Exploit

    Analysis and exploitation of CVE-2025-38617, a race condition based use-after-free vulnerability in the Linux kernel’s packet socket subsystem (@calif_io) https://blog.calif.io/p/a-race-within-a-race-exploiting-cve #Linux #infosec https://t.co/Q6oWLni1KA

    Post summary

    The post announces analysis and exploitation of a race‑condition use‑after‑free flaw in the Linux kernel’s packet socket subsystem, providing technical details but not indicating active attacks, patches, or a false‑positive status.

    1210123546.2K
    88.4K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets https://blog.calif.io/p/a-race-within-a-race-exploiting-cve

    Post summary

    The blog post title indicates the presence of a proof‑of‑concept exploitation for CVE‑2025‑38617 in Linux packet sockets, but the provided excerpt lacks details about the exploit code, active attacks, patches, or technical specifics.

    05030142.4K
    152.4K followersView on X
  • Constantin Milos ♏@Tinolle infosec.exchange@Tinolle1955
    PoC

    A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets.. A step-by-step guide to exploiting a 20-year-old bug in the Linux kernel..  https://blog.calif.io/p/a-race-within-a-race-exploiting-cve

    Post summary

    The post offers a step‑by‑step proof‑of‑concept for exploiting a long‑standing Linux kernel bug (CVE‑2025‑38617), emphasizing the exploitation technique while omitting patch information or evidence of active attacks.

    06022131.7K
    4.6K followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Exploiting CVE-2025-38617 in Linux Packet Sockets https://blog.calif.io/p/a-race-within-a-race-exploiting-cve

    Post summary

    The post points to a Bounty-based blog that likely contains a proof‑of‑concept for CVE‑2025‑38617 in Linux packet sockets, but it offers no explicit exploit code, patches, or evidence of active exploitation.

    13017122.3K
    152.4K followersView on X
  • Mr. OS@ksg93rd
    Exploit

    #exploit #Kernel_Security A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets https://blog.calif.io/p/a-race-within-a-race-exploiting-cve // A step-by-step guide to exploiting a 20-year-old bug in the Linux kernel to achieve full privilege escalation and container escape, plus a cool bug-hunting heuristic

    Post summary

    The post advertises a step‑by‑step guide to exploit CVE‑2025‑38617, detailing how to achieve privilege escalation and container escape using a 20‑year‑old bug in Linux packet sockets.

    020102628
    3.1K followersView on X
  • felipehuici@felipehuici
    Active Exploitation

    If you're running critical or multi-tenant workloads on containers, you're playing with fire. The CVE record keeps proving it: - CVE-2024-21626 — Leaky Vessels: runc container escape, host filesystem access - CVE-2025-23266 — NVIDIAScape: CVSS 9.0, triggered by a 3-line Dockerfile - CVE-2025-52881 — runc procfs write-redirect: full breakout, actively exploited in the wild by mid-2026 - CVE-2025-38617 — Linux kernel packet-socket: full container escape via user namespaces This is not a 2024 phenomenon that someone will eventually fix. The November-2025 runc trio (CVE-2025-31133 / -52565 / -52881) moved from disclosure to confirmed in-the-wild exploitation, affecting Docker, containerd and every major managed Kubernetes service. Escapes never stopped — 2024-2025 brought a fresh surge, and by 2026 the worst of them are being exploited for real. Containers don't contain. ⚠️ 📄 Full blog post: https://unikraft.com/blog/the-mighty-microvm

    Post summary

    The post warns that several recent container‑escape CVEs, especially the 2025 runc trio, are already being exploited in the wild, urging operators of critical or multi‑tenant workloads to reassess the risk.

    00066569
    909 followersView on X
  • /r/netsec@_r_netsec
    General

    A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets https://blog.calif.io/p/a-race-within-a-race-exploiting-cve

    Post summary

    The excerpt points to a blog post discussing exploitation of CVE‑2025‑38617 in Linux packet sockets, but offers only high‑level context without concrete PoC, exploit code, or patch details.

    020731.1K
    32.8K followersView on X
  • Dr. Harish Gupta@DrGuptaGRC
    Exploit

    I tested Composer 2.5 Fast vs GPT-5.5 Thinking on a real CVE that came out 3 days ago-> Drupal CVE-2026-9082, a critical SQL injection. Each run was a fresh session, new folder and file names, so that model wont recognize. Both models found the bug all 3 runs. Composer 2.5 Fast:- Run 1: nailed it. Gave a working exploit payload. Rated it High severity. Run 2: missed the point. Called it a "Low severity input validation issue. A real Audit would deprioritize this. Run 3: nailed it again. Even caught a bonus issue GPT missed. GPT-5.5 Thinking:- All 3 runs: detected the bug, rated it "Medium", never gave an exploit payload. Run 3 said "less likely full SQL injection" -> basically the same dismissal Composer had in Run 2. Note: Actual CVE rating is "Highly Critical". Neither model got that right. Composer 2.5, runs gave detailed report but its variance is the real story benchmarks don't show. One run nails the exploit. The next run tells you to ignore it. 2nd Test: Tested Composer 2.5 Fast vs GPT-5.5 Thinking vs Gemini 3.5 Flash on a real Linux kernel CVE that came out 3 weeks ago -> CVE-2026-31700, a TOCTOU race condition in net/packet/af_packet.c. Each run was a fresh session, new folder and file names, so that model wont recognize. 3 runs per model, 9 runs total. T The actual bug: vnet_hdr points into mmap'd memory shared with userspace. Kernel validates it once, then re-reads it later. Userspace can modify between validation and use. Race conditions are notoriously hard for LLMs because there is no pattern in the code, the bug lives in execution timing. Composer 2.5 Fast:- Run 1: nailed it. Severity Critical (slightly overrated, actual is High). 10 issues total. Run 2: nailed it again. CWE-367, exact lines, 3-step exploit flow. Even cross-referenced CVE-2025-38617. Run 3: best run of all 9. Explicitly named CVE-2026-31700, stated the actual upstream fix, found 2 bonus TOCTOU variants. GPT-5.5 Thinking:- Run 1: clean pass. Identified TOCTOU on mmap shared ring. Severity High (exactly matches CVSS 7.8). Run 2: complete failure. Found OOB read, MTU bypass, integer underflow. Never said "race" or "TOCTOU". Run 3: recovered. Solid pass. Gemini 3.5 Flash:- 0 for 3. Three different wrong CVEs across three runs. Historical AF_PACKET integer overflow, then signed/unsigned conversion, then CVE-2017-7308. Confident, detailed, wrong every time. @skcd42 @yunta_tsai @mntruell @amanrsanger @sualehasif996

    Post summary

    The post compares AI models on two recent CVEs, highlighting that Composer 2.5 Fast delivered a working exploit payload for the Drupal SQL injection and detailed exploit flow for a Linux kernel TOCTOU bug, while other models had mixed success.

    00052828
    546 followersView on X
  • Dr. Harish Gupta@DrGuptaGRC
    Patch

    2nd Test: Tested Composer 2.5 Fast vs GPT-5.5 Thinking vs Gemini 3.5 Flash on a real Linux kernel CVE that came out 3 weeks ago -> CVE-2026-31700, a TOCTOU race condition in net/packet/af_packet.c. Each run was a fresh session, new folder and file names, so that model wont recognize. 3 runs per model, 9 runs total. The actual bug: vnet_hdr points into mmap'd memory shared with userspace. Kernel validates it once, then re-reads it later. Userspace can modify between validation and use. Race conditions are notoriously hard for LLMs because there is no pattern in the code, the bug lives in execution timing. Composer 2.5 Fast:- Run 1: nailed it. Severity Critical (slightly overrated, actual is High). 10 issues total. Run 2: nailed it again. CWE-367, exact lines, 3-step exploit flow. Even cross-referenced CVE-2025-38617. Run 3: best run of all 9. Explicitly named CVE-2026-31700, stated the actual upstream fix, found 2 bonus TOCTOU variants. GPT-5.5 Thinking:- Run 1: clean pass. Identified TOCTOU on mmap shared ring. Severity High (exactly matches CVSS 7.8). Run 2: complete failure. Found OOB read, MTU bypass, integer underflow. Never said "race" or "TOCTOU". Run 3: recovered. Solid pass. Gemini 3.5 Flash:- 0 for 3. Three different wrong CVEs across three runs. Historical AF_PACKET integer overflow, then signed/unsigned conversion, then CVE-2017-7308. Confident, detailed, wrong every time. @skcd42 @yunta_tsai @mntruell @amanrsanger @sualehasif996

    Post summary

    The post details the CVE‑2026‑31700 TOCTOU race in the Linux kernel, provides technical insights, and notes an upstream fix, but makes no claim of active exploitation or provides a PoC.

    00001158
    263 followersView on X
  • Komodo Cyber Security@Komodosec
    Exploit

    A Race Within A Race: Exploiting CVE-2025-38617 in Linux Packet Sockets https://blog.calif.io/p/a-race-within-a-race-exploiting-cve?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The post references a CVE and links to a blog that appears to discuss exploitation, but the snippet itself provides no concrete PoC, code, or technical specifics.

    01000189
    1.5K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-54236 2 - CVE-2025-38617 3 - CVE-2026-21513 4 - CVE-2026-3102 5 - CVE-2017-7921 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVEs without offering any further technical or actionable information.

    00010173
    1.7K followersView on X
  • VulnTracker@vuln_tracker
    General

    This CVE-2025-38617 analysis is outstanding! Linux kernel race conditions are notoriously tricky to exploit, and your technical diagrams showing the packet socket subsystem vulnerability make it accessible to the security community. Track and monitor this CVE: https://vulntracker.io/cves/CVE-2025-38617

    Post summary

    The tweet praises the analysis of CVE-2025-38617 and encourages monitoring, but provides no PoC, exploit details, patch info, or technical specifics.

    00001204
    394 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-23222 2 - CVE-2026-22719 3 - CVE-2026-25611 4 - CVE-2025-38617 5 - CVE-2026-21902 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet merely lists five CVE identifiers as trending topics, offering no additional technical or exploit information.

    00010232
    1.7K followersView on X
  • Angsuman Chakraborty ✪@angsuman
    Exploit

    A Race Within a Race: Exploiting CVE-2025-38617 in Linux Packet Sockets https://blog.calif.io/p/a-race-within-a-race-exploiting-cve

    Post summary

    The post links to a blog that discusses exploiting CVE-2025-38617, but the text itself provides no concrete details on PoCs, tools, active exploitation, patches, or technical specifics.

    00000131
    7.5K followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    @linkersec This "Race Within A Race" analysis of CVE-2025-38617 is incredible! The packet sockets UAF exploitation with pgv array manipulation shows serious kernel research. Quang Le's technical breakdown is exactly what the community needs. Track it now: https://vulntracker.io/cves/CVE-2025-38617

    Post summary

    The post highlights a technical analysis of CVE‑2025‑38617, detailing a use‑after‑free in packet sockets with pgv array manipulation, but does not discuss exploits, patches, or active attacks.

    00000106
    426 followersView on X
  • dbugs@ptdbugs
    General

    Exploitation of CVE-2025-38617 in Linux Packet Sockets The article examines the exploitation of a race condition vulnerability in the Linux kernel’s packet socket subsystem (CVE-2025-38617 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2025-38617)). The flaw allows an attacker to achieve local privilege escalation (LPE). The issue arises from concurrent access to network packet buffers and extended file attributes, creating a window for kernel memory corruption. Exploitation requires only local system access and can ultimately lead to arbitrary code execution with root privileges. 📎 Article: https://blog.calif.io/p/a-race-within-a-race-exploiting-cve #dbugs_attacks

    Post summary

    The post describes the race-condition flaw in Linux packet sockets (CVE‑2025‑38617) that allows local privilege escalation, without presenting explicit exploit code or evidence of in‑the‑wild attacks.

    00000141
    614 followersView on X
  • Zymeralabs@Zymeralabs
    Disclosure

    CVE-2025-38617 es una vulnerabilidad use-after-free en el subsistema de packet sockets del kernel Linux, causada por una race condition. El bug existía desde Linux 2.6.12 (2005) y fue corregido en la versión 6.16. 20 años en producción. Sin que nadie lo viera ¿Cuántos + habrá? https://t.co/vaMKKOIY6I

    Post summary

    CVE‑2025‑38617 is a use‑after‑free race condition in the Linux kernel’s packet sockets, a flaw that existed since 2005 and has been patched in version 6.16; the post highlights its historical persistence and recent remediation.

    00000119
    4 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
OSlinuxlinux_kernel---
OSlinuxlinux_kernel2.6.12--
OSlinuxlinux_kernel2.6.12--
OSlinuxlinux_kernel2.6.12--
OSlinuxlinux_kernel2.6.12--
OSlinuxlinux_kernel2.6.12--

Explore more