CVE-2025-38461
MEDIUM EPSS 1.7%
Published Jul 25, 202511mo ago · Modified Jun 17, 20261w ago
4.7 CVSS 3.1
Published Jul 25, 2025 11mo ago
Last Modified Jun 17, 2026 1w ago
Description
In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_* TOCTOU Transport assignment may race with module unload. Protect new_transport from becoming a stale pointer. This also takes care of an insecure call in vsock_use_local_transport(); add a lockdep assert. BUG: unable to handle page fault for address: fffffbfff8056000 Oops: Oops: 0000 [#1] SMP KASAN RIP: 0010:vsock_assign_transport+0x366/0x600 Call Trace: vsock_connect+0x59c/0xc40 __sys_connect+0xe8/0x100 __x64_sys_connect+0x6e/0xc0 do_syscall_64+0x92/0x1c0 entry_SYSCALL_64_after_hwframe+0x4b/0x53
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High
Threat Intelligence
EPSS Exploit Probability
1.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-367
Affected Products 12
| Vendor | Product | Version | Range |
|---|---|---|---|
| linux | linux_kernel | * | ≥5.5 – <5.10.240 |
| linux | linux_kernel | * | ≥5.11 – <5.15.189 |
| linux | linux_kernel | * | ≥5.16 – <6.1.146 |
| linux | linux_kernel | * | ≥6.2 – <6.6.99 |
| linux | linux_kernel | * | ≥6.7 – <6.12.39 |
| linux | linux_kernel | * | ≥6.13 – <6.15.7 |
| linux | linux_kernel | 6.16 | any |
| linux | linux_kernel | 6.16 | any |
| linux | linux_kernel | 6.16 | any |
| linux | linux_kernel | 6.16 | any |
| linux | linux_kernel | 6.16 | any |
| debian | debian_linux | 11.0 | any |
References 9
- git.kernel.org https://git.kernel.org/stable/c/36a439049b34cca0b3661276049b84a1f76cc21a
- git.kernel.org https://git.kernel.org/stable/c/687aa0c5581b8d4aa87fd92973e4ee576b550cdf
- git.kernel.org https://git.kernel.org/stable/c/7b73bddf54777fb62d4d8c7729d0affe6df04477
- git.kernel.org https://git.kernel.org/stable/c/8667e8d0eb46bc54fdae30ba2f4786407d3d88eb
- git.kernel.org https://git.kernel.org/stable/c/9ce53e744f18e73059d3124070e960f3aa9902bf
- git.kernel.org https://git.kernel.org/stable/c/9d24bb6780282b0255b9929abe5e8f98007e2c6e
- git.kernel.org https://git.kernel.org/stable/c/ae2c712ba39c7007de63cb0c75b51ce1caaf1da5
- lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
- lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
Remediation
- git.kernel.org https://git.kernel.org/stable/c/36a439049b34cca0b3661276049b84a1f76cc21a
- git.kernel.org https://git.kernel.org/stable/c/687aa0c5581b8d4aa87fd92973e4ee576b550cdf
- git.kernel.org https://git.kernel.org/stable/c/7b73bddf54777fb62d4d8c7729d0affe6df04477
- git.kernel.org https://git.kernel.org/stable/c/8667e8d0eb46bc54fdae30ba2f4786407d3d88eb
- git.kernel.org https://git.kernel.org/stable/c/9ce53e744f18e73059d3124070e960f3aa9902bf
- git.kernel.org https://git.kernel.org/stable/c/9d24bb6780282b0255b9929abe5e8f98007e2c6e
- git.kernel.org https://git.kernel.org/stable/c/ae2c712ba39c7007de63cb0c75b51ce1caaf1da5