{
	"document":{
		"aggregate_severity":{
			"namespace":"https://nvd.nist.gov/vuln-metrics/cvss",
			"text":"MEDIUM"
		},
		"category":"csaf_vex",
		"csaf_version":"2.0",
		"distribution":{
			"tlp":{
				"label":"WHITE",
				"url":"https:/www.first.org/tlp/"
			}
		},
		"lang":"en",
		"notes":[
			{
				"text":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/mlx5: Fix potential deadlock in MR deregistration\n\nThe issue arises when kzalloc() is invoked while holding umem_mutex or\nany other lock acquired under umem_mutex. This is problematic because\nkzalloc() can trigger fs_reclaim_aqcuire(), which may, in turn, invoke\nmmu_notifier_invalidate_range_start(). This function can lead to\nmlx5_ib_invalidate_range(), which attempts to acquire umem_mutex again,\nresulting in a deadlock.\n\nThe problematic flow:\n             CPU0                      |              CPU1\n---------------------------------------|------------------------------------------------\nmlx5_ib_dereg_mr()                     |\n → revoke_mr()                         |\n   → mutex_lock(&umem_odp->umem_mutex) |\n                                       | mlx5_mkey_cache_init()\n                                       |  → mutex_lock(&dev->cache.rb_lock)\n                                       |  → mlx5r_cache_create_ent_locked()\n                                       |    → kzalloc(GFP_KERNEL)\n                                       |      → fs_reclaim()\n                                       |        → mmu_notifier_invalidate_range_start()\n                                       |          → mlx5_ib_invalidate_range()\n                                       |            → mutex_lock(&umem_odp->umem_mutex)\n   → cache_ent_find_and_store()        |\n     → mutex_lock(&dev->cache.rb_lock) |\n\nAdditionally, when kzalloc() is called from within\ncache_ent_find_and_store(), we encounter the same deadlock due to\nre-acquisition of umem_mutex.\n\nSolve by releasing umem_mutex in dereg_mr() after umr_revoke_mr()\nand before acquiring rb_lock. This ensures that we don't hold\numem_mutex while performing memory allocations that could trigger\nthe reclaim path.\n\nThis change prevents the deadlock by ensuring proper lock ordering and\navoiding holding locks during memory allocation operations that could\ntrigger the reclaim path.\n\nThe following lockdep warning demonstrates the deadlock:\n\n python3/20557 is trying to acquire lock:\n ffff888387542128 (&umem_odp->umem_mutex){+.+.}-{4:4}, at:\n mlx5_ib_invalidate_range+0x5b/0x550 [mlx5_ib]\n\n but task is already holding lock:\n ffffffff82f6b840 (mmu_notifier_invalidate_range_start){+.+.}-{0:0}, at:\n unmap_vmas+0x7b/0x1a0\n\n which lock already depends on the new lock.\n\n the existing dependency chain (in reverse order) is:\n\n -> #3 (mmu_notifier_invalidate_range_start){+.+.}-{0:0}:\n       fs_reclaim_acquire+0x60/0xd0\n       mem_cgroup_css_alloc+0x6f/0x9b0\n       cgroup_init_subsys+0xa4/0x240\n       cgroup_init+0x1c8/0x510\n       start_kernel+0x747/0x760\n       x86_64_start_reservations+0x25/0x30\n       x86_64_start_kernel+0x73/0x80\n       common_startup_64+0x129/0x138\n\n -> #2 (fs_reclaim){+.+.}-{0:0}:\n       fs_reclaim_acquire+0x91/0xd0\n       __kmalloc_cache_noprof+0x4d/0x4c0\n       mlx5r_cache_create_ent_locked+0x75/0x620 [mlx5_ib]\n       mlx5_mkey_cache_init+0x186/0x360 [mlx5_ib]\n       mlx5_ib_stage_post_ib_reg_umr_init+0x3c/0x60 [mlx5_ib]\n       __mlx5_ib_add+0x4b/0x190 [mlx5_ib]\n       mlx5r_probe+0xd9/0x320 [mlx5_ib]\n       auxiliary_bus_probe+0x42/0x70\n       really_probe+0xdb/0x360\n       __driver_probe_device+0x8f/0x130\n       driver_probe_device+0x1f/0xb0\n       __driver_attach+0xd4/0x1f0\n       bus_for_each_dev+0x79/0xd0\n       bus_add_driver+0xf0/0x200\n       driver_register+0x6e/0xc0\n       __auxiliary_driver_register+0x6a/0xc0\n       do_one_initcall+0x5e/0x390\n       do_init_module+0x88/0x240\n       init_module_from_file+0x85/0xc0\n       idempotent_init_module+0x104/0x300\n       __x64_sys_finit_module+0x68/0xc0\n       do_syscall_64+0x6d/0x140\n       entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\n -> #1 (&dev->cache.rb_lock){+.+.}-{4:4}:\n       __mutex_lock+0x98/0xf10\n       __mlx5_ib_dereg_mr+0x6f2/0x890 [mlx5_ib]\n       mlx5_ib_dereg_mr+0x21/0x110 [mlx5_ib]\n       ib_dereg_mr_user+0x85/0x1f0 [ib_core]\n  \n---truncated---",
				"category":"general",
				"title":"Synopsis"
			}
		],
		"publisher":null,
		"references":[
			{
				"summary":"nvd cve",
				"category":"external",
				"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-38373"
			},
			{
				"summary":"CVE-2025-38373 vex file",
				"category":"self",
				"url":"https://repo.openeuler.org/security/data/csaf/cve/2025/csaf-openeuler-cve-2025-38373.json"
			},
			{
				"summary":"openEuler-SA-2026-1761",
				"category":"self",
				"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-1761"
			},
			{
				"summary":"CVE-2025-38373",
				"category":"self",
				"url":"https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-38373&packageName=kernel"
			}
		],
		"title":"openEuler cve CVE-2025-38373",
		"tracking":{
			"initial_release_date":"2026-03-30T15:49:39+08:00",
			"revision_history":[
				{
					"date":"2026-03-30T15:49:39+08:00",
					"summary":"Initial",
					"number":"1.0.0"
				}
			],
			"generator":{
				"date":"2026-03-30T15:49:39+08:00",
				"engine":{
					"name":"openEuler CSAF Tool V1.0"
				}
			},
			"current_release_date":"2026-03-30T15:49:39+08:00",
			"id":"CVE-2025-38373",
			"version":"1.0.0",
			"status":"interim"
		}
	},
	"product_tree":{
		"branches":[
			{
				"name":"openEuler",
				"category":"vendor",
				"branches":[
					{
						"name":"openEuler",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"openEuler-24.03-LTS-SP2",
									"name":"openEuler-24.03-LTS-SP2"
								},
								"name":"openEuler-24.03-LTS-SP2",
								"category":"product_version"
							}
						],
						"category":"product_name"
					},
					{
						"name":"aarch64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"bpftool-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"bpftool-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"bpftool-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"bpftool-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"bpftool-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"bpftool-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"kernel-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"kernel-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"kernel-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"kernel-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-debugsource-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"kernel-debugsource-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"kernel-debugsource-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-devel-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"kernel-devel-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"kernel-devel-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-extra-modules-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"kernel-extra-modules-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"kernel-extra-modules-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-headers-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"kernel-headers-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"kernel-headers-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-source-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"kernel-source-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"kernel-source-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-tools-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"kernel-tools-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"kernel-tools-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-tools-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"kernel-tools-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"kernel-tools-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-tools-devel-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"kernel-tools-devel-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"kernel-tools-devel-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"perf-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"perf-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"perf-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"python3-perf-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"python3-perf-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"python3-perf-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"python3-perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
									"name":"python3-perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm"
								},
								"name":"python3-perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"x86_64",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"bpftool-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"bpftool-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"bpftool-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"bpftool-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"bpftool-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"bpftool-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"kernel-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"kernel-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"kernel-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"kernel-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-debugsource-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"kernel-debugsource-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"kernel-debugsource-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-devel-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"kernel-devel-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"kernel-devel-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-extra-modules-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"kernel-extra-modules-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"kernel-extra-modules-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-headers-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"kernel-headers-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"kernel-headers-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-source-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"kernel-source-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"kernel-source-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-tools-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"kernel-tools-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"kernel-tools-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-tools-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"kernel-tools-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"kernel-tools-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-tools-devel-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"kernel-tools-devel-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"kernel-tools-devel-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"perf-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"perf-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"perf-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"python3-perf-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"python3-perf-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"python3-perf-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							},
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"python3-perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
									"name":"python3-perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm"
								},
								"name":"python3-perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					},
					{
						"name":"src",
						"branches":[
							{
								"product":{
									"product_identification_helper":{
										"cpe":"cpe:/a:openEuler:openEuler:24.03-LTS-SP2"
									},
									"product_id":"kernel-6.6.0-144.0.0.140.oe2403sp2.src.rpm",
									"name":"kernel-6.6.0-144.0.0.140.oe2403sp2.src.rpm"
								},
								"name":"kernel-6.6.0-144.0.0.140.oe2403sp2.src.rpm",
								"category":"product_version"
							}
						],
						"category":"architecture"
					}
				]
			}
		],
		"relationships":[
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"bpftool-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:bpftool-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"bpftool-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"bpftool-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:bpftool-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"bpftool-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"kernel-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"kernel-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-debugsource-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-debugsource-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"kernel-debugsource-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-devel-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-devel-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"kernel-devel-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-extra-modules-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-extra-modules-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"kernel-extra-modules-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-headers-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-headers-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"kernel-headers-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-source-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-source-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"kernel-source-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-tools-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-tools-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"kernel-tools-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-tools-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-tools-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"kernel-tools-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-tools-devel-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-tools-devel-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"kernel-tools-devel-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"perf-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:perf-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"perf-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"python3-perf-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:python3-perf-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"python3-perf-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"python3-perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:python3-perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64",
					"name":"python3-perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.aarch64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"bpftool-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:bpftool-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"bpftool-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"bpftool-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:bpftool-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"bpftool-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"kernel-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"kernel-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-debugsource-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-debugsource-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"kernel-debugsource-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-devel-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-devel-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"kernel-devel-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-extra-modules-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-extra-modules-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"kernel-extra-modules-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-headers-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-headers-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"kernel-headers-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-source-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-source-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"kernel-source-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-tools-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-tools-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"kernel-tools-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-tools-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-tools-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"kernel-tools-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-tools-devel-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-tools-devel-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"kernel-tools-devel-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"perf-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:perf-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"perf-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"python3-perf-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:python3-perf-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"python3-perf-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"python3-perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:python3-perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64",
					"name":"python3-perf-debuginfo-6.6.0-144.0.0.140.oe2403sp2.x86_64 as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			},
			{
				"relates_to_product_reference":"openEuler-24.03-LTS-SP2",
				"product_reference":"kernel-6.6.0-144.0.0.140.oe2403sp2.src.rpm",
				"full_product_name":{
					"product_id":"openEuler-24.03-LTS-SP2:kernel-6.6.0-144.0.0.140.oe2403sp2.src",
					"name":"kernel-6.6.0-144.0.0.140.oe2403sp2.src as a component of openEuler-24.03-LTS-SP2"
				},
				"category":"default_component_of"
			}
		]
	},
	"vulnerabilities":[
		{
			"cve":"CVE-2025-38373",
			"notes":[
				{
					"text":"In the Linux kernel, the following vulnerability has been resolved:\n\nIB/mlx5: Fix potential deadlock in MR deregistration\n\nThe issue arises when kzalloc() is invoked while holding umem_mutex or\nany other lock acquired under umem_mutex. This is problematic because\nkzalloc() can trigger fs_reclaim_aqcuire(), which may, in turn, invoke\nmmu_notifier_invalidate_range_start(). This function can lead to\nmlx5_ib_invalidate_range(), which attempts to acquire umem_mutex again,\nresulting in a deadlock.\n\nThe problematic flow:\n             CPU0                      |              CPU1\n---------------------------------------|------------------------------------------------\nmlx5_ib_dereg_mr()                     |\n → revoke_mr()                         |\n   → mutex_lock(&umem_odp->umem_mutex) |\n                                       | mlx5_mkey_cache_init()\n                                       |  → mutex_lock(&dev->cache.rb_lock)\n                                       |  → mlx5r_cache_create_ent_locked()\n                                       |    → kzalloc(GFP_KERNEL)\n                                       |      → fs_reclaim()\n                                       |        → mmu_notifier_invalidate_range_start()\n                                       |          → mlx5_ib_invalidate_range()\n                                       |            → mutex_lock(&umem_odp->umem_mutex)\n   → cache_ent_find_and_store()        |\n     → mutex_lock(&dev->cache.rb_lock) |\n\nAdditionally, when kzalloc() is called from within\ncache_ent_find_and_store(), we encounter the same deadlock due to\nre-acquisition of umem_mutex.\n\nSolve by releasing umem_mutex in dereg_mr() after umr_revoke_mr()\nand before acquiring rb_lock. This ensures that we don't hold\numem_mutex while performing memory allocations that could trigger\nthe reclaim path.\n\nThis change prevents the deadlock by ensuring proper lock ordering and\navoiding holding locks during memory allocation operations that could\ntrigger the reclaim path.\n\nThe following lockdep warning demonstrates the deadlock:\n\n python3/20557 is trying to acquire lock:\n ffff888387542128 (&umem_odp->umem_mutex){+.+.}-{4:4}, at:\n mlx5_ib_invalidate_range+0x5b/0x550 [mlx5_ib]\n\n but task is already holding lock:\n ffffffff82f6b840 (mmu_notifier_invalidate_range_start){+.+.}-{0:0}, at:\n unmap_vmas+0x7b/0x1a0\n\n which lock already depends on the new lock.\n\n the existing dependency chain (in reverse order) is:\n\n -> #3 (mmu_notifier_invalidate_range_start){+.+.}-{0:0}:\n       fs_reclaim_acquire+0x60/0xd0\n       mem_cgroup_css_alloc+0x6f/0x9b0\n       cgroup_init_subsys+0xa4/0x240\n       cgroup_init+0x1c8/0x510\n       start_kernel+0x747/0x760\n       x86_64_start_reservations+0x25/0x30\n       x86_64_start_kernel+0x73/0x80\n       common_startup_64+0x129/0x138\n\n -> #2 (fs_reclaim){+.+.}-{0:0}:\n       fs_reclaim_acquire+0x91/0xd0\n       __kmalloc_cache_noprof+0x4d/0x4c0\n       mlx5r_cache_create_ent_locked+0x75/0x620 [mlx5_ib]\n       mlx5_mkey_cache_init+0x186/0x360 [mlx5_ib]\n       mlx5_ib_stage_post_ib_reg_umr_init+0x3c/0x60 [mlx5_ib]\n       __mlx5_ib_add+0x4b/0x190 [mlx5_ib]\n       mlx5r_probe+0xd9/0x320 [mlx5_ib]\n       auxiliary_bus_probe+0x42/0x70\n       really_probe+0xdb/0x360\n       __driver_probe_device+0x8f/0x130\n       driver_probe_device+0x1f/0xb0\n       __driver_attach+0xd4/0x1f0\n       bus_for_each_dev+0x79/0xd0\n       bus_add_driver+0xf0/0x200\n       driver_register+0x6e/0xc0\n       __auxiliary_driver_register+0x6a/0xc0\n       do_one_initcall+0x5e/0x390\n       do_init_module+0x88/0x240\n       init_module_from_file+0x85/0xc0\n       idempotent_init_module+0x104/0x300\n       __x64_sys_finit_module+0x68/0xc0\n       do_syscall_64+0x6d/0x140\n       entry_SYSCALL_64_after_hwframe+0x4b/0x53\n\n -> #1 (&dev->cache.rb_lock){+.+.}-{4:4}:\n       __mutex_lock+0x98/0xf10\n       __mlx5_ib_dereg_mr+0x6f2/0x890 [mlx5_ib]\n       mlx5_ib_dereg_mr+0x21/0x110 [mlx5_ib]\n       ib_dereg_mr_user+0x85/0x1f0 [ib_core]\n  \n---truncated---",
					"category":"description",
					"title":"Vulnerability Description"
				}
			],
			"product_status":{
				"fixed":{
					"$ref":"$.vulnerabilities[0].product_status.fixed"
				}
			},
			"remediations":[
				{
					"product_ids":{
						"$ref":"$.vulnerabilities[0].product_status.fixed"
					},
					"details":"kernel security update",
					"category":"vendor_fix",
					"url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-1761"
				}
			],
			"scores":[
				{
					"cvss_v3":{
						"baseSeverity":"MEDIUM",
						"baseScore":5.5,
						"vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
						"version":"3.1"
					},
					"products":{
						"$ref":"$.vulnerabilities[0].product_status.fixed"
					}
				}
			],
			"threats":[
				{
					"details":"Medium",
					"category":"impact"
				}
			],
			"title":"CVE-2025-38373"
		}
	]
}