CVE-2025-21718 Information
Description
In the Linux kernel the following vulnerability has been resolved:
net: rose: fix timer races against user threads
Rose timers only acquire the socket spinlock without checking if the socket is owned by one user thread.
Add a check and rearm the timers if needed.
BUG: KASAN: slab-use-after-free in rose_timer_expiry+0x31d/0x360 net/rose/rose_timer.c:174 Read of size 2 at addr ffff88802f09b82a by task swapper/0/0
CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.13.0-rc5-syzkaller-00172-gd1bf27c4e176 0
Hardware name: Google Google Compute Engine/Google Compute Engine BIOS Google 09/13/2024
Call Trace:
Reference
https://git.kernel.org/stable/c/1992fb261c90e9827cf5dc3115d89bb0853252c9 https://git.kernel.org/stable/c/51c128ba038cf1b79d605cbee325919b45ab95a5 https://git.kernel.org/stable/c/58051a284ac18a3bb815aac6289a679903ddcc3f https://git.kernel.org/stable/c/5de7665e0a0746b5ad7943554b34db8f8614a196 https://git.kernel.org/stable/c/f55c88e3ca5939a6a8a329024aed8f3d98eea8e4
Share on: