<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 11:06:24 +0000</lastBuildDate>
    <item>
      <title>CVE-2025-21999 — proc: fix UAF in proc_get_inode()</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2025-21999</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;proc: fix UAF in proc_get_inode()&lt;/p&gt;
&lt;p&gt;Fix race between rmmod and /proc/XXX&amp;#39;s inode instantiation.&lt;/p&gt;
&lt;p&gt;The bug is that pde-&amp;gt;proc_ops don&amp;#39;t belong to /proc, it belongs to a
module, therefore dereferencing it after /proc entry has been registered
is a bug unless use_pde/unuse_pde() pair has been used.&lt;/p&gt;
&lt;p&gt;use_pde/unuse_pde can be avoided (2 atomic ops!) because pde-&amp;gt;proc_ops
never changes so information necessary for inode instantiation can be
saved _before_ proc_register() in PDE itself and used later, avoiding
pde-&amp;gt;proc_ops-&amp;gt;...  dereference.&lt;/p&gt;
&lt;p&gt;rmmod                         lookup
sys_delete_module
                         proc_lookup_de
			   pde_get(de);
			   proc_get_inode(dir-&amp;gt;i_sb, de);
  mod-&amp;gt;exit()
    proc_remove
      remove_proc_subtree
       proc_entry_rundown(de);
  free_module(mod);&lt;/p&gt;
&lt;p&gt;if (S_ISREG(inode-&amp;gt;i_mode))
	                         if (de-&amp;gt;proc_ops-&amp;gt;proc_read_iter)
                           --&amp;gt; As module is already freed, will trigger UAF&lt;/p&gt;
&lt;p&gt;BUG: unable to handle page fault for address: fffffbfff80a702b
PGD 817fc4067 P4D 817fc4067 PUD 817fc0067 PMD 102ef4067 PTE 0
Oops: Oops: 0000 [#1] PREEMPT SMP KASAN PTI
CPU: 26 UID: 0 PID: 2667 Comm: ls Tainted: G
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)
RIP: 0010:proc_get_inode+0x302/0x6e0
RSP: 0018:ffff88811c837998 EFLAGS: 00010a06
RAX: dffffc0000000000 RBX: ffffffffc0538140 RCX: 0000000000000007
RDX: 1ffffffff…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Linux, Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP, Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;proc: fix UAF in proc_get_inode()&lt;/p&gt;
&lt;p&gt;Fix race between rmmod and /proc/XXX&amp;#39;s inode instantiation.&lt;/p&gt;
&lt;p&gt;The bug is that pde-&amp;gt;proc_ops don&amp;#39;t belong to /proc, it belongs to a
module, therefore dereferencing it after /proc entry has been registered
is a bug unless use_pde/unuse_pde() pair has been used.&lt;/p&gt;
&lt;p&gt;use_pde/unuse_pde can be avoided (2 atomic ops!) because pde-&amp;gt;proc_ops
never changes so information necessary for inode instantiation can be
saved _before_ proc_register() in PDE itself and used later, avoiding
pde-&amp;gt;proc_ops-&amp;gt;...  dereference.&lt;/p&gt;
&lt;p&gt;rmmod                         lookup
sys_delete_module
                         proc_lookup_de
			   pde_get(de);
			   proc_get_inode(dir-&amp;gt;i_sb, de);
  mod-&amp;gt;exit()
    proc_remove
      remove_proc_subtree
       proc_entry_rundown(de);
  free_module(mod);&lt;/p&gt;
&lt;p&gt;if (S_ISREG(inode-&amp;gt;i_mode))
	                         if (de-&amp;gt;proc_ops-&amp;gt;proc_read_iter)
                           --&amp;gt; As module is already freed, will trigger UAF&lt;/p&gt;
&lt;p&gt;BUG: unable to handle page fault for address: fffffbfff80a702b
PGD 817fc4067 P4D 817fc4067 PUD 817fc0067 PMD 102ef4067 PTE 0
Oops: Oops: 0000 [#1] PREEMPT SMP KASAN PTI
CPU: 26 UID: 0 PID: 2667 Comm: ls Tainted: G
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996)
RIP: 0010:proc_get_inode+0x302/0x6e0
RSP: 0018:ffff88811c837998 EFLAGS: 00010a06
RAX: dffffc0000000000 RBX: ffffffffc0538140 RCX: 0000000000000007
RDX: 1ffffffff…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2025-21999</guid>
    </item>
  </channel>
</rss>
