CVE-2025-38462
Description
In the Linux kernel, the following vulnerability has been resolved:vsock: Fix transport_{g2h,h2g} TOCTOUvsock_find_cid() and vsock_dev_do_ioctl() may race with module unload.transport_{g2h,h2g} may become null after the null check.Introduce vsock_transport_local_cid() to protect from a potentialnull-ptr-deref.KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]RIP: 0010:vsock_find_cid+0x47/0x90Call Trace: __vsock_bind+0x4b2/0x720 vsock_bind+0x90/0xe0 __sys_bind+0x14d/0x1e0 __x64_sys_bind+0x6e/0xc0 do_syscall_64+0x92/0x1c0 entry_SYSCALL_64_after_hwframe+0x4b/0x53KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]RIP: 0010:vsock_dev_do_ioctl.isra.0+0x58/0xf0Call Trace: __x64_sys_ioctl+0x12d/0x190 do_syscall_64+0x92/0x1c0 entry_SYSCALL_64_after_hwframe+0x4b/0x53
Risk Information
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| linux security update(DSA-5973-1) DSA-5973-1 linux-cpupower_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-doc_6.1.147-1_all.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-doc-6.1_6.1.147-1_all.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-686-dbg_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-686-pae-dbg_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-cpupower_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-amd64-signed-template_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-cloud-amd64-dbg_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-i386-signed-template_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-rt-686-pae-dbg_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-rt-amd64-dbg_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-image-amd64-dbg_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-config-6.1_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-config-6.1_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-compiler-gcc-12-x86_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-kbuild-6.1_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 libcpupower1_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 libcpupower1_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 libcpupower-dev_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 libcpupower-dev_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 hyperv-daemons_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 hyperv-daemons_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 bpftool_7.1.0+6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-compiler-gcc-12-x86_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 usbip_2.0+6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 usbip_2.0+6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 rtla_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 rtla_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-source-6.1_6.1.147-1_all.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-source_6.1.147-1_all.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-libc-dev_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 bpftool_7.1.0+6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-libc-dev_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-perf_6.1.147-1_amd64.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-kbuild-6.1_6.1.147-1_i386.deb | Linux |
| linux security update(DSA-5973-1) DSA-5973-1 linux-perf_6.1.147-1_i386.deb | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234