CVE-2025-38461

MEDIUM EPSS 1.7%
Published Jul 25, 202511mo ago · Modified Jun 17, 20261w ago
4.7 CVSS 3.1
Medium
Find Similar
Published Jul 25, 2025 11mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_* TOCTOU Transport assignment may race with module unload. Protect new_transport from becoming a stale pointer. This also takes care of an insecure call in vsock_use_local_transport(); add a lockdep assert. BUG: unable to handle page fault for address: fffffbfff8056000 Oops: Oops: 0000 [#1] SMP KASAN RIP: 0010:vsock_assign_transport+0x366/0x600 Call Trace: vsock_connect+0x59c/0xc40 __sys_connect+0xe8/0x100 __x64_sys_connect+0x6e/0xc0 do_syscall_64+0x92/0x1c0 entry_SYSCALL_64_after_hwframe+0x4b/0x53

CVSS Details

Base Score
4.7
Exploitability
1.0
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity High
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
1.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-367

Affected Products 12

VendorProductVersionRange
linuxlinux_kernel*≥5.5  –  <5.10.240
linuxlinux_kernel*≥5.11  –  <5.15.189
linuxlinux_kernel*≥5.16  –  <6.1.146
linuxlinux_kernel*≥6.2  –  <6.6.99
linuxlinux_kernel*≥6.7  –  <6.12.39
linuxlinux_kernel*≥6.13  –  <6.15.7
linuxlinux_kernel6.16any
linuxlinux_kernel6.16any
linuxlinux_kernel6.16any
linuxlinux_kernel6.16any
linuxlinux_kernel6.16any
debiandebian_linux11.0any

References 9

  • git.kernel.org https://git.kernel.org/stable/c/36a439049b34cca0b3661276049b84a1f76cc21a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/687aa0c5581b8d4aa87fd92973e4ee576b550cdf
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7b73bddf54777fb62d4d8c7729d0affe6df04477
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8667e8d0eb46bc54fdae30ba2f4786407d3d88eb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9ce53e744f18e73059d3124070e960f3aa9902bf
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9d24bb6780282b0255b9929abe5e8f98007e2c6e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ae2c712ba39c7007de63cb0c75b51ce1caaf1da5
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
    Third Party Advisory
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
    Third Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/36a439049b34cca0b3661276049b84a1f76cc21a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/687aa0c5581b8d4aa87fd92973e4ee576b550cdf
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7b73bddf54777fb62d4d8c7729d0affe6df04477
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8667e8d0eb46bc54fdae30ba2f4786407d3d88eb
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9ce53e744f18e73059d3124070e960f3aa9902bf
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9d24bb6780282b0255b9929abe5e8f98007e2c6e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/ae2c712ba39c7007de63cb0c75b51ce1caaf1da5
    Patch