5.5

CVE-2025-21666

vsock: prevent null-ptr-deref in vsock_*[has_data|has_space]

In the Linux kernel, the following vulnerability has been resolved:

vsock: prevent null-ptr-deref in vsock_*[has_data|has_space]

Recent reports have shown how we sometimes call vsock_*_has_data()
when a vsock socket has been de-assigned from a transport (see attached
links), but we shouldn't.

Previous commits should have solved the real problems, but we may have
more in the future, so to avoid null-ptr-deref, we can return 0
(no space, no data available) but with a warning.

This way the code should continue to run in a nearly consistent state
and have a warning that allows us to debug future problems.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 5.5 < 5.15.177
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.127
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.74
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.11
Linux ≫ Linux Kernel Version 6.13 Update rc1
Linux ≫ Linux Kernel Version 6.13 Update rc2
Linux ≫ Linux Kernel Version 6.13 Update rc3
Linux ≫ Linux Kernel Version 6.13 Update rc4
Linux ≫ Linux Kernel Version 6.13 Update rc5
Linux ≫ Linux Kernel Version 6.13 Update rc6
Linux ≫ Linux Kernel Version 6.13 Update rc7
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.123
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CISA-ADP 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://git.kernel.org/stable/c/91751e248256efc111e52e15115840c35d85abaf
Patch
https://git.kernel.org/stable/c/9e5fed46ccd2c34c5fa5a9c8825ce4823fdc853e
Patch
https://git.kernel.org/stable/c/b52e50dd4fabd12944172bd486a4f4853b7f74dd
Patch
https://git.kernel.org/stable/c/bc9c49341f9728c31fe248c5fbba32d2e81a092b
Patch
https://git.kernel.org/stable/c/c23d1d4f8efefb72258e9cedce29de10d057f8ca
Patch
https://git.kernel.org/stable/c/daeac89cdb03d30028186f5ff7dc26ec8fa843e7
Patch
https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html
https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html
https://cert-portal.siemens.com/productcert/html/ssa-265688.html