CVE-2025-38102 | Linux Kernel up to 6.15.2 VMCI mm/gup.c vmci_host_setup_notify race condition (EUVD-2025-19840 / Nessus ID 249177)
A vulnerability was found in Linux Kernel up to 5.15.185/6.1.141/6.6.93/6.12.33/6.15.2. It has been rated as problematic. Affected by this vulnerability is the function vmci_host_setup_notify of the file mm/gup.c of the component VMCI. The manipulation leads to race condition.
This vulnerability is traded as CVE-2025-38102. Access to the local network is required for this attack to succeed. There is no exploit available.
Upgrading the affected component is advised.