CVE-2025-40242
Published Dec 4, 2025
Modified Apr 15, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: gfs2: Fix unlikely race in gdlm_put_lock In gdlm_put_lock(), there is a small window of time in which the DFL_UNMOUNT flag has been set but the lockspace hasn't been released, yet. In that window, dlm may still call gdlm_ast() and gdlm_bast(). To prevent it from dereferencing freed glock objects, only free the glock if the lockspace has actually been released.
Is your site exposed to CVE-2025-40242?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/279bde3bbb0ac0bad5c729dfa85983d75a5d7641
https://git.kernel.org/stable/c/28c4d9bc0708956c1a736a9e49fee71b65deee81
https://git.kernel.org/stable/c/4913592a3358f6ec366b8346b733d5e2360b08e1
https://git.kernel.org/stable/c/5fdc1474e678eea1700aa266c0b7c2c96f81dd0d
https://git.kernel.org/stable/c/64c61b4ac645222fa7b724cef616c1f862a72a40
Frequently Asked Questions
What is CVE-2025-40242? +
In the Linux kernel, the following vulnerability has been resolved:
gfs2: Fix unlikely race in gdlm_put_lock
In gdlm_put_lock(), there is a small window of time in which the
DFL_UNMOUNT flag has been set but the lockspace hasn't been released,
yet. In that window, dlm may still call gdlm_ast() and gdlm_bast().
To prevent it from dereferencing freed glock objects, only free the
glock if the lockspace has actually been released.
How do I check if I'm vulnerable to CVE-2025-40242? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.