-

CVE-2025-38462

In the Linux kernel, the following vulnerability has been resolved:

vsock: Fix transport_{g2h,h2g} TOCTOU

vsock_find_cid() and vsock_dev_do_ioctl() may race with module unload.
transport_{g2h,h2g} may become NULL after the NULL check.

Introduce vsock_transport_local_cid() to protect from a potential
null-ptr-deref.

KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]
RIP: 0010:vsock_find_cid+0x47/0x90
Call Trace:
 __vsock_bind+0x4b2/0x720
 vsock_bind+0x90/0xe0
 __sys_bind+0x14d/0x1e0
 __x64_sys_bind+0x6e/0xc0
 do_syscall_64+0x92/0x1c0
 entry_SYSCALL_64_after_hwframe+0x4b/0x53

KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]
RIP: 0010:vsock_dev_do_ioctl.isra.0+0x58/0xf0
Call Trace:
 __x64_sys_ioctl+0x12d/0x190
 do_syscall_64+0x92/0x1c0
 entry_SYSCALL_64_after_hwframe+0x4b/0x53

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLinux
Product Linux
Default Statusunaffected
Version < c5496ee685c48ed1cc183cd4263602579bb4a615
Version c0cfa2d8a788fcf45df5bf4070ab2474c88d543a
Status affected
Version < 80d7dc15805a93d520a249ac6d13d4f4df161c1b
Version c0cfa2d8a788fcf45df5bf4070ab2474c88d543a
Status affected
Version < 5752d8dbb3dfd7f1a9faf0f65377e60826ea9a17
Version c0cfa2d8a788fcf45df5bf4070ab2474c88d543a
Status affected
Version < 401239811fa728fcdd53e360a91f157ffd23e1f4
Version c0cfa2d8a788fcf45df5bf4070ab2474c88d543a
Status affected
Version < 3734d78210cceb2ee5615719a62a5c55ed381ff8
Version c0cfa2d8a788fcf45df5bf4070ab2474c88d543a
Status affected
Version < 6a1bcab67bea797d83aa9dd948a0ac6ed52d121d
Version c0cfa2d8a788fcf45df5bf4070ab2474c88d543a
Status affected
Version < 209fd720838aaf1420416494c5505096478156b4
Version c0cfa2d8a788fcf45df5bf4070ab2474c88d543a
Status affected
VendorLinux
Product Linux
Default Statusaffected
Version 5.5
Status affected
Version < 5.5
Version 0
Status unaffected
Version <= 5.10.*
Version 5.10.240
Status unaffected
Version <= 5.15.*
Version 5.15.189
Status unaffected
Version <= 6.1.*
Version 6.1.146
Status unaffected
Version <= 6.6.*
Version 6.6.99
Status unaffected
Version <= 6.12.*
Version 6.12.39
Status unaffected
Version <= 6.15.*
Version 6.15.7
Status unaffected
Version <= *
Version 6.16
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.103
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string