<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T10:38:59.628434+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2025-21865</id>
    <title>CVE-2025-21865 — gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl().</title>
    <updated>2026-10-09T10:38:59.630802+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Linux, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP</p>
<p>In the Linux kernel, the following vulnerability has been resolved:</p>
<p>gtp: Suppress list corruption splat in gtp_net_exit_batch_rtnl().</p>
<p>Brad Spengler reported the list_del() corruption splat in
gtp_net_exit_batch_rtnl(). [0]</p>
<p>Commit eb28fd76c0a0 ("gtp: Destroy device along with udp socket's netns
dismantle.") added the for_each_netdev() loop in gtp_net_exit_batch_rtnl()
to destroy devices in each netns as done in geneve and ip tunnels.</p>
<p>However, this could trigger -&gt;dellink() twice for the same device during
-&gt;exit_batch_rtnl().</p>
<p>Say we have two netns A &amp; B and gtp device B that resides in netns B but
whose UDP socket is in netns A.</p>
<p>1. cleanup_net() processes netns A and then B.</p>
<p>2. gtp_net_exit_batch_rtnl() finds the device B while iterating
     netns A's gn-&gt;gtp_dev_list and calls -&gt;dellink().</p>
<p>[ device B is not yet unlinked from netns B
    as unregister_netdevice_many() has not been called. ]</p>
<p>3. gtp_net_exit_batch_rtnl() finds the device B while iterating
     netns B's for_each_netdev() and calls -&gt;dellink().</p>
<p>gtp_dellink() cleans up the device's hash table, unlinks the dev from
gn-&gt;gtp_dev_list, and calls unregister_netdevice_queue().</p>
<p>Basically, calling gtp_dellink() multiple times is fine unless
CONFIG_DEBUG_LIST is enabled.</p>
<p>Let's remove for_each_netdev() in gtp_net_exit_batch_rtnl() and
delegate the destruction to default_device_exit_batch() as done
in bareudp.</p>
<p>[0]:
list_del corruption, ffff8880aaa62c00-&gt;next (autoslab_size_M_dev_P_net_core_dev_11127_8_…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2025-21865"/>
  </entry>
</feed>
