Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在代码问题漏洞,该漏洞源于vsock_bpf_recvmsg函数在未分配传输层时未正确检查vsk->transport,导致在尝试接收数据时可能访问空指针,引发内核崩溃。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 634f1a7110b439c65fd8a809171c1d2d28bcea6f< 58e586c30d0b6f5dc0174a41026f2b0a48c9aab6 |
affected |
634f1a7110b439c65fd8a809171c1d2d28bcea6f< 6771e1279dadf1d92a72e1465134257d9e6f2459 |
affected | ||
634f1a7110b439c65fd8a809171c1d2d28bcea6f< f6abafcd32f9cfc4b1a2f820ecea70773e26d423 |
affected | ||
6.4 |
affected | ||
< 6.4 |
unaffected | ||
6.6.74≤ 6.6.* |
unaffected | ||
6.12.11≤ 6.12.* |
unaffected | ||
6.13≤ * |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-21673 | 9.8 CRITICAL | smb: client: fix double free of TCP_Server_Info::hostname |
| CVE-2025-21680 | 7.8 HIGH | pktgen: Avoid out-of-bounds access in get_imix_entries |
| CVE-2025-21678 | 7.8 HIGH | gtp: Destroy device along with udp socket's netns dismantle. |
| CVE-2025-21677 | 7.8 HIGH | pfcp: Destroy device along with udp socket's netns dismantle. |
| CVE-2025-21669 | 7.8 HIGH | vsock/virtio: discard packets if the transport changes |
| CVE-2025-21676 | 7.5 HIGH | net: fec: handle page_pool_dev_alloc_pages error |
| CVE-2025-21682 | 7.3 HIGH | eth: bnxt: always recalculate features after XDP clearing, fix null-deref |
| CVE-2024-57948 | mac802154: check local interfaces before deleting sdata list | |
| CVE-2025-21683 | bpf: Fix bpf_sk_select_reuseport() memory leak | |
| CVE-2025-21665 | filemap: avoid truncating 64-bit offset to 32 bits | |
| CVE-2025-21666 | vsock: prevent null-ptr-deref in vsock_*[has_data|has_space] | |
| CVE-2025-21667 | iomap: avoid avoid truncating 64-bit offset to 32 bits | |
| CVE-2025-21668 | pmdomain: imx8mp-blk-ctrl: add missing loop break condition | |
| CVE-2025-21671 | zram: fix potential UAF of zram table | |
| CVE-2025-21672 | afs: Fix merge preference rule failure condition | |
| CVE-2025-21674 | net/mlx5e: Fix inversion dependency warning while enabling IPsec tunnel | |
| CVE-2025-21675 | net/mlx5: Clear port select structure when fail to create | |
| CVE-2025-21679 | btrfs: add the missing error handling inside get_canonical_dev_path | |
| CVE-2025-21681 | openvswitch: fix lockup on tx to unregistering netdev with carrier |
No comments yet