---
id: CVE-2025-38614
title: 'eventpoll: Fix semi-unbounded recursion'
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  eventpoll: Fix semi-unbounded recursion

  Ensure that epoll instances can never form a graph deeper than
  EP_MAX_NESTS+1 links.

  Currently, ep_loop_check_proc() ensures t…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <
    71379495ab70eaba19224bd71b5b9b399eb85e04
  - >-
    Linux >= 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <
    1b13b033062824495554e836a1ff5f85ccf6b039
  - >-
    Linux >= 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <
    2a0c0c974bea9619c6f41794775ae4b97530e0e6
  - >-
    Linux >= 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <
    7a2125962c42d5336ca0495a9ce4cb38a63e9161
  - >-
    Linux >= 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <
    ea5f97dbdcb1651581a22bd10afd2f0dd9dc11d6
  - >-
    Linux >= 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <
    3542c90797bc3ab83ebab54b737d751cf3682036
  - >-
    Linux >= 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e <
    f2e467a48287c868818085aa35389a224d226732
  - Linux 8216e1a0d47cae06a75c42346f19dffe14e42d57
  - Linux 28a92748aa4bc57d35e7b079498b0ac2e7610a37
  - Linux 7eebcd4792c5a341559aed327b6afecbb1c46402
  - Linux 0eccd188cfeaf857a26f2d72941d27d298cf6a54
  - Linux a72affdbb09f3f24f64ffcbbdf62c2e57c58f379
  - Linux >= 2.6.32.30 < 2.6.33
  - Linux >= 2.6.33.8 < 2.6.34
  - Linux >= 2.6.34.10 < 2.6.35
  - Linux >= 2.6.35.12 < 2.6.36
  - Linux >= 2.6.37.3 < 2.6.38
  - Linux 2.6.38
published: '2025-08-19'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T08:41:53.814Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2025-38614'
references:
  - url: 'https://git.kernel.org/stable/c/71379495ab70eaba19224bd71b5b9b399eb85e04'
  - url: 'https://git.kernel.org/stable/c/1b13b033062824495554e836a1ff5f85ccf6b039'
  - url: 'https://git.kernel.org/stable/c/2a0c0c974bea9619c6f41794775ae4b97530e0e6'
  - url: 'https://git.kernel.org/stable/c/7a2125962c42d5336ca0495a9ce4cb38a63e9161'
  - url: 'https://git.kernel.org/stable/c/ea5f97dbdcb1651581a22bd10afd2f0dd9dc11d6'
  - url: 'https://git.kernel.org/stable/c/3542c90797bc3ab83ebab54b737d751cf3682036'
  - url: 'https://git.kernel.org/stable/c/f2e467a48287c868818085aa35389a224d226732'
tags:
  - cve.org
epss: 0.00177
epssPercentile: 0.06559
ingestedAt: '2026-09-08T15:33:26.997Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

eventpoll: Fix semi-unbounded recursion

Ensure that epoll instances can never form a graph deeper than
EP_MAX_NESTS+1 links.

Currently, ep_loop_check_proc() ensures that the graph is loop-free and
does some recursion depth checks, but those recursion depth checks don't
limit the depth of the resulting tree for two reasons:

 - They don't look upwards in the tree.
 - If there are multiple downwards paths of different lengths, only one of
   the paths is actually considered for the depth check since commit
   28d82dc1c4ed ("epoll: limit paths").

Essentially, the current recursion depth check in ep_loop_check_proc() just
serves to prevent it from recursing too deeply while checking for loops.

A more thorough check is done in reverse_path_check() after the new graph
edge has already been created; this checks, among other things, that no
paths going upwards from any non-epoll file with a length of more than 5
edges exist. However, this check does not apply to non-epoll files.

As a result, it is possible to recurse to a depth of at least roughly 500,
tested on v6.15. (I am unsure if deeper recursion is possible; and this may
have changed with commit 8c44dac8add7 ("eventpoll: Fix priority inversion
problem").)

To fix it:

1. In ep_loop_check_proc(), note the subtree depth of each visited node,
and use subtree depths for the total depth calculation even when a subtree
has already been visited.
2. Add ep_get_upwards_depth_proc() for similarly determining the maximum
depth of an upwards walk.
3. In ep_loop_check(), use these values to limit the total path length
between epoll nodes to EP_MAX_NESTS edges.

## Affected

- `Linux >= 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e < 71379495ab70eaba19224bd71b5b9b399eb85e04`
- `Linux >= 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e < 1b13b033062824495554e836a1ff5f85ccf6b039`
- `Linux >= 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e < 2a0c0c974bea9619c6f41794775ae4b97530e0e6`
- `Linux >= 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e < 7a2125962c42d5336ca0495a9ce4cb38a63e9161`
- `Linux >= 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e < ea5f97dbdcb1651581a22bd10afd2f0dd9dc11d6`
- `Linux >= 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e < 3542c90797bc3ab83ebab54b737d751cf3682036`
- `Linux >= 22bacca48a1755f79b7e0f192ddb9fbb7fc6e64e < f2e467a48287c868818085aa35389a224d226732`
- `Linux 8216e1a0d47cae06a75c42346f19dffe14e42d57`
- `Linux 28a92748aa4bc57d35e7b079498b0ac2e7610a37`
- `Linux 7eebcd4792c5a341559aed327b6afecbb1c46402`
- `Linux 0eccd188cfeaf857a26f2d72941d27d298cf6a54`
- `Linux a72affdbb09f3f24f64ffcbbdf62c2e57c58f379`
- `Linux >= 2.6.32.30 < 2.6.33`
- `Linux >= 2.6.33.8 < 2.6.34`
- `Linux >= 2.6.34.10 < 2.6.35`
- `Linux >= 2.6.35.12 < 2.6.36`
- `Linux >= 2.6.37.3 < 2.6.38`
- `Linux 2.6.38`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
