CVE-2025-38180

HIGH EPSS 6.7%
Published Jul 4, 202512mo ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
High
Find Similar
Published Jul 4, 2025 12mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix /proc/net/atm/lec handling /proc/net/atm/lec must ensure safety against dev_lec[] changes. It appears it had dev_put() calls without prior dev_hold(), leading to imbalance and UAF.

CVSS Details

Base Score
7.8
Exploitability
1.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
6.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-416 Use After Free Memory Safety

Affected Products 15

VendorProductVersionRange
linuxlinux_kernel*≥2.6.13  –  <5.4.295
linuxlinux_kernel*≥5.5  –  <5.10.239
linuxlinux_kernel*≥5.11  –  <5.15.186
linuxlinux_kernel*≥5.16  –  <6.1.142
linuxlinux_kernel*≥6.2  –  <6.6.95
linuxlinux_kernel*≥6.7  –  <6.12.35
linuxlinux_kernel*≥6.13  –  <6.15.4
linuxlinux_kernel2.6.12any
linuxlinux_kernel2.6.12any
linuxlinux_kernel2.6.12any
linuxlinux_kernel2.6.12any
linuxlinux_kernel2.6.12any
linuxlinux_kernel6.16any
linuxlinux_kernel6.16any
debiandebian_linux11.0any

References 10

  • git.kernel.org https://git.kernel.org/stable/c/5fe1b23a2f87f43aeeac51e08819cbc6fd808cbc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9b9aeb3ada44d8abea1e31e4446113f460848ae4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a5e3a144268899f1a8c445c8a3bfa15873ba85e8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ca3829c18c8d0ceb656605d3bff6bb3dfb078589
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d03b79f459c7935cff830d98373474f440bd03ae
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e612c4b014f5808fbc6beae21f5ccaca5e76a2f8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f2d1443b18806640abdb530e88009af7be2588e7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fcfccf56f4eba7d00aa2d33c7bb1b33083237742
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
    Third Party Advisory
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
    Third Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/5fe1b23a2f87f43aeeac51e08819cbc6fd808cbc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9b9aeb3ada44d8abea1e31e4446113f460848ae4
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a5e3a144268899f1a8c445c8a3bfa15873ba85e8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ca3829c18c8d0ceb656605d3bff6bb3dfb078589
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d03b79f459c7935cff830d98373474f440bd03ae
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e612c4b014f5808fbc6beae21f5ccaca5e76a2f8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f2d1443b18806640abdb530e88009af7be2588e7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fcfccf56f4eba7d00aa2d33c7bb1b33083237742
    Patch