We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-21666

vsock: prevent null-ptr-deref in vsock_*[has_data|has_space]



Description

In the Linux kernel, the following vulnerability has been resolved: vsock: prevent null-ptr-deref in vsock_*[has_data|has_space] Recent reports have shown how we sometimes call vsock_*_has_data() when a vsock socket has been de-assigned from a transport (see attached links), but we shouldn't. Previous commits should have solved the real problems, but we may have more in the future, so to avoid null-ptr-deref, we can return 0 (no space, no data available) but with a warning. This way the code should continue to run in a nearly consistent state and have a warning that allows us to debug future problems.

Reserved 2024-12-29 | Published 2025-01-31 | Updated 2025-02-02 | Assigner Linux

Product status

Default status
unaffected

c0cfa2d8a788fcf45df5bf4070ab2474c88d543a before daeac89cdb03d30028186f5ff7dc26ec8fa843e7
affected

c0cfa2d8a788fcf45df5bf4070ab2474c88d543a before 9e5fed46ccd2c34c5fa5a9c8825ce4823fdc853e
affected

c0cfa2d8a788fcf45df5bf4070ab2474c88d543a before b52e50dd4fabd12944172bd486a4f4853b7f74dd
affected

c0cfa2d8a788fcf45df5bf4070ab2474c88d543a before bc9c49341f9728c31fe248c5fbba32d2e81a092b
affected

c0cfa2d8a788fcf45df5bf4070ab2474c88d543a before c23d1d4f8efefb72258e9cedce29de10d057f8ca
affected

c0cfa2d8a788fcf45df5bf4070ab2474c88d543a before 91751e248256efc111e52e15115840c35d85abaf
affected

Default status
affected

5.5
affected

Any version before 5.5
unaffected

5.10.234
unaffected

5.15.177
unaffected

6.1.127
unaffected

6.6.74
unaffected

6.12.11
unaffected

6.13
unaffected

References

git.kernel.org/...c/daeac89cdb03d30028186f5ff7dc26ec8fa843e7

git.kernel.org/...c/9e5fed46ccd2c34c5fa5a9c8825ce4823fdc853e

git.kernel.org/...c/b52e50dd4fabd12944172bd486a4f4853b7f74dd

git.kernel.org/...c/bc9c49341f9728c31fe248c5fbba32d2e81a092b

git.kernel.org/...c/c23d1d4f8efefb72258e9cedce29de10d057f8ca

git.kernel.org/...c/91751e248256efc111e52e15115840c35d85abaf

cve.org (CVE-2025-21666)

nvd.nist.gov (CVE-2025-21666)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2025-21666

Support options

Helpdesk Chat, Email, Knowledgebase
Subscribe to our newsletter to learn more about our work.