-

CVE-2025-38461

In the Linux kernel, the following vulnerability has been resolved:

vsock: Fix transport_* TOCTOU

Transport assignment may race with module unload. Protect new_transport
from becoming a stale pointer.

This also takes care of an insecure call in vsock_use_local_transport();
add a lockdep assert.

BUG: unable to handle page fault for address: fffffbfff8056000
Oops: Oops: 0000 [#1] SMP KASAN
RIP: 0010:vsock_assign_transport+0x366/0x600
Call Trace:
 vsock_connect+0x59c/0xc40
 __sys_connect+0xe8/0x100
 __x64_sys_connect+0x6e/0xc0
 do_syscall_64+0x92/0x1c0
 entry_SYSCALL_64_after_hwframe+0x4b/0x53

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version < 8667e8d0eb46bc54fdae30ba2f4786407d3d88eb
Version c0cfa2d8a788fcf45df5bf4070ab2474c88d543a
Status affected
Version < 36a439049b34cca0b3661276049b84a1f76cc21a
Version c0cfa2d8a788fcf45df5bf4070ab2474c88d543a
Status affected
Version < 9ce53e744f18e73059d3124070e960f3aa9902bf
Version c0cfa2d8a788fcf45df5bf4070ab2474c88d543a
Status affected
Version < 9d24bb6780282b0255b9929abe5e8f98007e2c6e
Version c0cfa2d8a788fcf45df5bf4070ab2474c88d543a
Status affected
Version < ae2c712ba39c7007de63cb0c75b51ce1caaf1da5
Version c0cfa2d8a788fcf45df5bf4070ab2474c88d543a
Status affected
Version < 7b73bddf54777fb62d4d8c7729d0affe6df04477
Version c0cfa2d8a788fcf45df5bf4070ab2474c88d543a
Status affected
Version < 687aa0c5581b8d4aa87fd92973e4ee576b550cdf
Version c0cfa2d8a788fcf45df5bf4070ab2474c88d543a
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.5
Status affected
Version < 5.5
Version 0
Status unaffected
Version <= 5.10.*
Version 5.10.240
Status unaffected
Version <= 5.15.*
Version 5.15.189
Status unaffected
Version <= 6.1.*
Version 6.1.146
Status unaffected
Version <= 6.6.*
Version 6.6.99
Status unaffected
Version <= 6.12.*
Version 6.12.39
Status unaffected
Version <= 6.15.*
Version 6.15.7
Status unaffected
Version <= *
Version 6.16
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.103
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String