Search

Find a vulnerability

Search criteria

    24 vulnerabilities found for SIMATIC S7-1500 TM MFP - BIOS by Siemens

    CVE-2025-21826 (GCVE-0-2025-21826)

    Vulnerability from nvd – Published: 2025-03-06 16:04 – Updated: 2026-08-05 11:54
    VLAI
    Title
    netfilter: nf_tables: reject mismatching sum of field_len with set key length
    Summary
    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject mismatching sum of field_len with set key length The field length description provides the length of each separated key field in the concatenation, each field gets rounded up to 32-bits to calculate the pipapo rule width from pipapo_init(). The set key length provides the total size of the key aligned to 32-bits. Register-based arithmetics still allows for combining mismatching set key length and field length description, eg. set key length 10 and field description [ 5, 4 ] leading to pipapo width of 12.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 2d4c0798a1ef8db15b3277697ac2def4eda42312 , < 6b467c8feac759f4c5c86d708beca2aa2b29584f (git)
    Affected: 77be8c495a3f841e88b46508cc20d3d7d3289da3 , < 5083a7ae45003456c253e981b30a43f71230b4a3 (git)
    Affected: 9cb084df01e198119de477ac691d682fb01e80f3 , < 2ac254343d3cf228ae0738b2615fedf85d000752 (git)
    Affected: dc45bb00e66a33de1abb29e3d587880e1d4d9a7e , < 82e491e085719068179ff6a5466b7387cc4bbf32 (git)
    Affected: 3ce67e3793f48c1b9635beb9bb71116ca1e51b58 , < 49b7182b97bafbd5645414aff054b4a65d05823d (git)
    Affected: 3ce67e3793f48c1b9635beb9bb71116ca1e51b58 , < ab50d0eff4a939d20c37721fd9766347efcdb6f6 (git)
    Affected: 3ce67e3793f48c1b9635beb9bb71116ca1e51b58 , < 1b9335a8000fb70742f7db10af314104b6ace220 (git)
    Affected: ff67e3e488090908dc015ba04d7407d8bd467f7e (git)
    Affected: 5.10.209 , < 5.10.235 (semver)
    Affected: 5.15.148 , < 5.15.179 (semver)
    Affected: 6.1.75 , < 6.1.129 (semver)
    Affected: 6.6.14 , < 6.6.76 (semver)
    Affected: 6.7.2 , < 6.8 (semver)
    Create a notification for this product.
    Linux Linux Affected: 6.8
    Unaffected: 0 , < 6.8 (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.129 , ≤ 6.1.* (semver)
    Unaffected: 6.6.76 , ≤ 6.6.* (semver)
    Unaffected: 6.12.13 , ≤ 6.12.* (semver)
    Unaffected: 6.13.2 , ≤ 6.13.* (semver)
    Unaffected: 6.14 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:59:57.565Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:03:59.800Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/netfilter/nf_tables_api.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "6b467c8feac759f4c5c86d708beca2aa2b29584f",
                  "status": "affected",
                  "version": "2d4c0798a1ef8db15b3277697ac2def4eda42312",
                  "versionType": "git"
                },
                {
                  "lessThan": "5083a7ae45003456c253e981b30a43f71230b4a3",
                  "status": "affected",
                  "version": "77be8c495a3f841e88b46508cc20d3d7d3289da3",
                  "versionType": "git"
                },
                {
                  "lessThan": "2ac254343d3cf228ae0738b2615fedf85d000752",
                  "status": "affected",
                  "version": "9cb084df01e198119de477ac691d682fb01e80f3",
                  "versionType": "git"
                },
                {
                  "lessThan": "82e491e085719068179ff6a5466b7387cc4bbf32",
                  "status": "affected",
                  "version": "dc45bb00e66a33de1abb29e3d587880e1d4d9a7e",
                  "versionType": "git"
                },
                {
                  "lessThan": "49b7182b97bafbd5645414aff054b4a65d05823d",
                  "status": "affected",
                  "version": "3ce67e3793f48c1b9635beb9bb71116ca1e51b58",
                  "versionType": "git"
                },
                {
                  "lessThan": "ab50d0eff4a939d20c37721fd9766347efcdb6f6",
                  "status": "affected",
                  "version": "3ce67e3793f48c1b9635beb9bb71116ca1e51b58",
                  "versionType": "git"
                },
                {
                  "lessThan": "1b9335a8000fb70742f7db10af314104b6ace220",
                  "status": "affected",
                  "version": "3ce67e3793f48c1b9635beb9bb71116ca1e51b58",
                  "versionType": "git"
                },
                {
                  "status": "affected",
                  "version": "ff67e3e488090908dc015ba04d7407d8bd467f7e",
                  "versionType": "git"
                },
                {
                  "lessThan": "5.10.235",
                  "status": "affected",
                  "version": "5.10.209",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.15.179",
                  "status": "affected",
                  "version": "5.15.148",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.1.129",
                  "status": "affected",
                  "version": "6.1.75",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.6.76",
                  "status": "affected",
                  "version": "6.6.14",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.8",
                  "status": "affected",
                  "version": "6.7.2",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/netfilter/nf_tables_api.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.8"
                },
                {
                  "lessThan": "6.8",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.129",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.76",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.13",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.13.*",
                  "status": "unaffected",
                  "version": "6.13.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.14",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "5.10.209",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "5.15.148",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.129",
                      "versionStartIncluding": "6.1.75",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.76",
                      "versionStartIncluding": "6.6.14",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.13",
                      "versionStartIncluding": "6.8",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13.2",
                      "versionStartIncluding": "6.8",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.14",
                      "versionStartIncluding": "6.8",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionStartIncluding": "6.7.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: reject mismatching sum of field_len with set key length\n\nThe field length description provides the length of each separated key\nfield in the concatenation, each field gets rounded up to 32-bits to\ncalculate the pipapo rule width from pipapo_init(). The set key length\nprovides the total size of the key aligned to 32-bits.\n\nRegister-based arithmetics still allows for combining mismatching set\nkey length and field length description, eg. set key length 10 and field\ndescription [ 5, 4 ] leading to pipapo width of 12."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The vulnerability is reached exclusively through nfnetlink/netlink configuration messages to the nf_tables subsystem (NFT_MSG_NEWSET / NFT_MSG_NEWSETELEM), which require local system access. Per kernel scoring guidance, netfilter/nftables netlink paths are Local.\nAC:L - Triggering is fully deterministic and entirely attacker-controlled: create an interval+concat set with any key length not a multiple of 4 (e.g. klen=10 with field description [5,4]) and add one ranged element. No race, no memory-layout luck, and pipapo is the only backend that accepts multi-field interval sets so the vulnerable code is always selected.\nPR:L - nfnetlink_rcv_msg() checks netlink_net_capable(skb, CAP_NET_ADMIN), which is satisfied against the network namespace\u0027s owning user namespace, so any unprivileged local user can obtain it with `unshare -Urn` and then create the malformed set. This is the standard unprivileged-user-namespace path used by public nftables exploits.\nUI:N - The attacker performs all steps themselves through netlink; no victim action, mount, or file open is needed.\nS:U - The out-of-bounds accesses and the corrupted pipapo state remain within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - pipapo consumes round_up(klen,4) bytes from buffers holding only klen, reading past the end of the heap-allocated element extension (key_end) and consuming uninitialized kernel stack bytes from the on-stack struct nft_set_elem. Those out-of-bounds values are baked into the set\u0027s lookup tables and can be recovered by an attacker probing match results through the packet path, yielding kernel heap/stack disclosure.\nI:H - Kernel data structures (the pipapo lookup and mapping tables) are populated from memory outside the intended key object, so set state is corrupted with out-of-bounds content and packet-matching verdicts, maps, and NAT decisions become dependent on that data. Consistent with kernel-CNA precedent for local nftables/ebtables out-of-bounds accesses, the memory-safety violation is treated as High integrity impact.\nA:H - The slab out-of-bounds read past the element extension is a KASAN-reportable memory-safety violation that panics on hardened/panic_on_warn configurations and can fault when the object abuts an unmapped region, and the corrupted range endpoints drive pipapo_expand() rule expansion from garbage. Any such kernel crash is scored High."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:54:43.241Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/6b467c8feac759f4c5c86d708beca2aa2b29584f"
            },
            {
              "url": "https://git.kernel.org/stable/c/5083a7ae45003456c253e981b30a43f71230b4a3"
            },
            {
              "url": "https://git.kernel.org/stable/c/2ac254343d3cf228ae0738b2615fedf85d000752"
            },
            {
              "url": "https://git.kernel.org/stable/c/82e491e085719068179ff6a5466b7387cc4bbf32"
            },
            {
              "url": "https://git.kernel.org/stable/c/49b7182b97bafbd5645414aff054b4a65d05823d"
            },
            {
              "url": "https://git.kernel.org/stable/c/ab50d0eff4a939d20c37721fd9766347efcdb6f6"
            },
            {
              "url": "https://git.kernel.org/stable/c/1b9335a8000fb70742f7db10af314104b6ace220"
            }
          ],
          "title": "netfilter: nf_tables: reject mismatching sum of field_len with set key length",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2025-21826",
        "datePublished": "2025-03-06T16:04:32.274Z",
        "dateReserved": "2024-12-29T08:45:45.775Z",
        "dateUpdated": "2026-08-05T11:54:43.241Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-21806 (GCVE-0-2025-21806)

    Vulnerability from nvd – Published: 2025-02-27 20:00 – Updated: 2026-05-12 12:03
    VLAI
    Title
    net: let net.core.dev_weight always be non-zero
    Summary
    In the Linux kernel, the following vulnerability has been resolved: net: let net.core.dev_weight always be non-zero The following problem was encountered during stability test: (NULL net_device): NAPI poll function process_backlog+0x0/0x530 \ returned 1, exceeding its budget of 0. ------------[ cut here ]------------ list_add double add: new=ffff88905f746f48, prev=ffff88905f746f48, \ next=ffff88905f746e40. WARNING: CPU: 18 PID: 5462 at lib/list_debug.c:35 \ __list_add_valid_or_report+0xf3/0x130 CPU: 18 UID: 0 PID: 5462 Comm: ping Kdump: loaded Not tainted 6.13.0-rc7+ RIP: 0010:__list_add_valid_or_report+0xf3/0x130 Call Trace: ? __warn+0xcd/0x250 ? __list_add_valid_or_report+0xf3/0x130 enqueue_to_backlog+0x923/0x1070 netif_rx_internal+0x92/0x2b0 __netif_rx+0x15/0x170 loopback_xmit+0x2ef/0x450 dev_hard_start_xmit+0x103/0x490 __dev_queue_xmit+0xeac/0x1950 ip_finish_output2+0x6cc/0x1620 ip_output+0x161/0x270 ip_push_pending_frames+0x155/0x1a0 raw_sendmsg+0xe13/0x1550 __sys_sendto+0x3bf/0x4e0 __x64_sys_sendto+0xdc/0x1b0 do_syscall_64+0x5b/0x170 entry_SYSCALL_64_after_hwframe+0x76/0x7e The reproduction command is as follows: sysctl -w net.core.dev_weight=0 ping 127.0.0.1 This is because when the napi's weight is set to 0, process_backlog() may return 0 and clear the NAPI_STATE_SCHED bit of napi->state, causing this napi to be re-polled in net_rx_action() until __do_softirq() times out. Since the NAPI_STATE_SCHED bit has been cleared, napi_schedule_rps() can be retriggered in enqueue_to_backlog(), causing this issue. Making the napi's weight always non-zero solves this problem. Triggering this issue requires system-wide admin (setting is not namespaced).
    Severity
    No CVSS data available.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < d0e0f9c8218826926d7692980c98236d9f21fd3c (git)
    Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < c337c08819a4ec49edfdcd8fc46fbee120d8a5b2 (git)
    Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < 0e2f1d93d287d544d26f8ff293ea820a8079b9f8 (git)
    Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < 5860abbf15eeb61838b5e32e721ba67b0aa84450 (git)
    Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < 6ce38b5a6a49e65bad163162a54cb3f104c40b48 (git)
    Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < 33e2168788f8fb5cb8bd4f36cb1ef37d1d34dada (git)
    Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < 1489824e5226a26841c70639ebd2d1aed390764b (git)
    Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < d1f9f79fa2af8e3b45cffdeef66e05833480148a (git)
    Create a notification for this product.
    Linux Linux Affected: 2.6.12
    Unaffected: 0 , < 2.6.12 (semver)
    Unaffected: 5.4.291 , ≤ 5.4.* (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.129 , ≤ 6.1.* (semver)
    Unaffected: 6.6.76 , ≤ 6.6.* (semver)
    Unaffected: 6.12.13 , ≤ 6.12.* (semver)
    Unaffected: 6.13.2 , ≤ 6.13.* (semver)
    Unaffected: 6.14 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:59:45.883Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:03:57.348Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/core/sysctl_net_core.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "d0e0f9c8218826926d7692980c98236d9f21fd3c",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                },
                {
                  "lessThan": "c337c08819a4ec49edfdcd8fc46fbee120d8a5b2",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                },
                {
                  "lessThan": "0e2f1d93d287d544d26f8ff293ea820a8079b9f8",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                },
                {
                  "lessThan": "5860abbf15eeb61838b5e32e721ba67b0aa84450",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                },
                {
                  "lessThan": "6ce38b5a6a49e65bad163162a54cb3f104c40b48",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                },
                {
                  "lessThan": "33e2168788f8fb5cb8bd4f36cb1ef37d1d34dada",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                },
                {
                  "lessThan": "1489824e5226a26841c70639ebd2d1aed390764b",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                },
                {
                  "lessThan": "d1f9f79fa2af8e3b45cffdeef66e05833480148a",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/core/sysctl_net_core.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.6.12"
                },
                {
                  "lessThan": "2.6.12",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.291",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.129",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.76",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.13",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.13.*",
                  "status": "unaffected",
                  "version": "6.13.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.14",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.291",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.129",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.76",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.13",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13.2",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.14",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: let net.core.dev_weight always be non-zero\n\nThe following problem was encountered during stability test:\n\n(NULL net_device): NAPI poll function process_backlog+0x0/0x530 \\\n\treturned 1, exceeding its budget of 0.\n------------[ cut here ]------------\nlist_add double add: new=ffff88905f746f48, prev=ffff88905f746f48, \\\n\tnext=ffff88905f746e40.\nWARNING: CPU: 18 PID: 5462 at lib/list_debug.c:35 \\\n\t__list_add_valid_or_report+0xf3/0x130\nCPU: 18 UID: 0 PID: 5462 Comm: ping Kdump: loaded Not tainted 6.13.0-rc7+\nRIP: 0010:__list_add_valid_or_report+0xf3/0x130\nCall Trace:\n? __warn+0xcd/0x250\n? __list_add_valid_or_report+0xf3/0x130\nenqueue_to_backlog+0x923/0x1070\nnetif_rx_internal+0x92/0x2b0\n__netif_rx+0x15/0x170\nloopback_xmit+0x2ef/0x450\ndev_hard_start_xmit+0x103/0x490\n__dev_queue_xmit+0xeac/0x1950\nip_finish_output2+0x6cc/0x1620\nip_output+0x161/0x270\nip_push_pending_frames+0x155/0x1a0\nraw_sendmsg+0xe13/0x1550\n__sys_sendto+0x3bf/0x4e0\n__x64_sys_sendto+0xdc/0x1b0\ndo_syscall_64+0x5b/0x170\nentry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe reproduction command is as follows:\n  sysctl -w net.core.dev_weight=0\n  ping 127.0.0.1\n\nThis is because when the napi\u0027s weight is set to 0, process_backlog() may\nreturn 0 and clear the NAPI_STATE_SCHED bit of napi-\u003estate, causing this\nnapi to be re-polled in net_rx_action() until __do_softirq() times out.\nSince the NAPI_STATE_SCHED bit has been cleared, napi_schedule_rps() can\nbe retriggered in enqueue_to_backlog(), causing this issue.\n\nMaking the napi\u0027s weight always non-zero solves this problem.\n\nTriggering this issue requires system-wide admin (setting is\nnot namespaced)."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T21:06:53.699Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/d0e0f9c8218826926d7692980c98236d9f21fd3c"
            },
            {
              "url": "https://git.kernel.org/stable/c/c337c08819a4ec49edfdcd8fc46fbee120d8a5b2"
            },
            {
              "url": "https://git.kernel.org/stable/c/0e2f1d93d287d544d26f8ff293ea820a8079b9f8"
            },
            {
              "url": "https://git.kernel.org/stable/c/5860abbf15eeb61838b5e32e721ba67b0aa84450"
            },
            {
              "url": "https://git.kernel.org/stable/c/6ce38b5a6a49e65bad163162a54cb3f104c40b48"
            },
            {
              "url": "https://git.kernel.org/stable/c/33e2168788f8fb5cb8bd4f36cb1ef37d1d34dada"
            },
            {
              "url": "https://git.kernel.org/stable/c/1489824e5226a26841c70639ebd2d1aed390764b"
            },
            {
              "url": "https://git.kernel.org/stable/c/d1f9f79fa2af8e3b45cffdeef66e05833480148a"
            }
          ],
          "title": "net: let net.core.dev_weight always be non-zero",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2025-21806",
        "datePublished": "2025-02-27T20:00:58.918Z",
        "dateReserved": "2024-12-29T08:45:45.771Z",
        "dateUpdated": "2026-05-12T12:03:57.348Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-21776 (GCVE-0-2025-21776)

    Vulnerability from nvd – Published: 2025-02-27 02:18 – Updated: 2026-05-12 12:03
    VLAI
    Title
    USB: hub: Ignore non-compliant devices with too many configs or interfaces
    Summary
    In the Linux kernel, the following vulnerability has been resolved: USB: hub: Ignore non-compliant devices with too many configs or interfaces Robert Morris created a test program which can cause usb_hub_to_struct_hub() to dereference a NULL or inappropriate pointer: Oops: general protection fault, probably for non-canonical address 0xcccccccccccccccc: 0000 [#1] SMP DEBUG_PAGEALLOC PTI CPU: 7 UID: 0 PID: 117 Comm: kworker/7:1 Not tainted 6.13.0-rc3-00017-gf44d154d6e3d #14 Hardware name: FreeBSD BHYVE/BHYVE, BIOS 14.0 10/17/2021 Workqueue: usb_hub_wq hub_event RIP: 0010:usb_hub_adjust_deviceremovable+0x78/0x110 ... Call Trace: <TASK> ? die_addr+0x31/0x80 ? exc_general_protection+0x1b4/0x3c0 ? asm_exc_general_protection+0x26/0x30 ? usb_hub_adjust_deviceremovable+0x78/0x110 hub_probe+0x7c7/0xab0 usb_probe_interface+0x14b/0x350 really_probe+0xd0/0x2d0 ? __pfx___device_attach_driver+0x10/0x10 __driver_probe_device+0x6e/0x110 driver_probe_device+0x1a/0x90 __device_attach_driver+0x7e/0xc0 bus_for_each_drv+0x7f/0xd0 __device_attach+0xaa/0x1a0 bus_probe_device+0x8b/0xa0 device_add+0x62e/0x810 usb_set_configuration+0x65d/0x990 usb_generic_driver_probe+0x4b/0x70 usb_probe_device+0x36/0xd0 The cause of this error is that the device has two interfaces, and the hub driver binds to interface 1 instead of interface 0, which is where usb_hub_to_struct_hub() looks. We can prevent the problem from occurring by refusing to accept hub devices that violate the USB spec by having more than one configuration or interface.
    Severity
    No CVSS data available.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < 49f077106fa07919a6a6dda99bb490dd1d1a8218 (git)
    Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < d343fe0fad5c1d689775f2dda24a85ce98e29566 (git)
    Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < d3a67adb365cdfdac4620daf38a82e57ca45806c (git)
    Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < c3720b04df84b5459050ae4e03ec7d545652f897 (git)
    Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < e905a0fca7bff0855d312c16f71e60e1773b393e (git)
    Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < 62d8f4c5454dd39aded4f343720d1c5a1803cfef (git)
    Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < 5b9778e1fe715700993ce436c152dc3b7df0b490 (git)
    Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < 2240fed37afbcdb5e8b627bc7ad986891100e05d (git)
    Create a notification for this product.
    Linux Linux Affected: 3.9
    Unaffected: 0 , < 3.9 (semver)
    Unaffected: 5.4.291 , ≤ 5.4.* (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.129 , ≤ 6.1.* (semver)
    Unaffected: 6.6.79 , ≤ 6.6.* (semver)
    Unaffected: 6.12.16 , ≤ 6.12.* (semver)
    Unaffected: 6.13.4 , ≤ 6.13.* (semver)
    Unaffected: 6.14 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:37:31.434Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:03:52.412Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/usb/core/hub.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "49f077106fa07919a6a6dda99bb490dd1d1a8218",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                },
                {
                  "lessThan": "d343fe0fad5c1d689775f2dda24a85ce98e29566",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                },
                {
                  "lessThan": "d3a67adb365cdfdac4620daf38a82e57ca45806c",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                },
                {
                  "lessThan": "c3720b04df84b5459050ae4e03ec7d545652f897",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                },
                {
                  "lessThan": "e905a0fca7bff0855d312c16f71e60e1773b393e",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                },
                {
                  "lessThan": "62d8f4c5454dd39aded4f343720d1c5a1803cfef",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                },
                {
                  "lessThan": "5b9778e1fe715700993ce436c152dc3b7df0b490",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                },
                {
                  "lessThan": "2240fed37afbcdb5e8b627bc7ad986891100e05d",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/usb/core/hub.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.9"
                },
                {
                  "lessThan": "3.9",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.291",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.129",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.79",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.16",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.13.*",
                  "status": "unaffected",
                  "version": "6.13.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.14",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.291",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.129",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.79",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.16",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13.4",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.14",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: hub: Ignore non-compliant devices with too many configs or interfaces\n\nRobert Morris created a test program which can cause\nusb_hub_to_struct_hub() to dereference a NULL or inappropriate\npointer:\n\nOops: general protection fault, probably for non-canonical address\n0xcccccccccccccccc: 0000 [#1] SMP DEBUG_PAGEALLOC PTI\nCPU: 7 UID: 0 PID: 117 Comm: kworker/7:1 Not tainted 6.13.0-rc3-00017-gf44d154d6e3d #14\nHardware name: FreeBSD BHYVE/BHYVE, BIOS 14.0 10/17/2021\nWorkqueue: usb_hub_wq hub_event\nRIP: 0010:usb_hub_adjust_deviceremovable+0x78/0x110\n...\nCall Trace:\n \u003cTASK\u003e\n ? die_addr+0x31/0x80\n ? exc_general_protection+0x1b4/0x3c0\n ? asm_exc_general_protection+0x26/0x30\n ? usb_hub_adjust_deviceremovable+0x78/0x110\n hub_probe+0x7c7/0xab0\n usb_probe_interface+0x14b/0x350\n really_probe+0xd0/0x2d0\n ? __pfx___device_attach_driver+0x10/0x10\n __driver_probe_device+0x6e/0x110\n driver_probe_device+0x1a/0x90\n __device_attach_driver+0x7e/0xc0\n bus_for_each_drv+0x7f/0xd0\n __device_attach+0xaa/0x1a0\n bus_probe_device+0x8b/0xa0\n device_add+0x62e/0x810\n usb_set_configuration+0x65d/0x990\n usb_generic_driver_probe+0x4b/0x70\n usb_probe_device+0x36/0xd0\n\nThe cause of this error is that the device has two interfaces, and the\nhub driver binds to interface 1 instead of interface 0, which is where\nusb_hub_to_struct_hub() looks.\n\nWe can prevent the problem from occurring by refusing to accept hub\ndevices that violate the USB spec by having more than one\nconfiguration or interface."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T21:06:12.467Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/49f077106fa07919a6a6dda99bb490dd1d1a8218"
            },
            {
              "url": "https://git.kernel.org/stable/c/d343fe0fad5c1d689775f2dda24a85ce98e29566"
            },
            {
              "url": "https://git.kernel.org/stable/c/d3a67adb365cdfdac4620daf38a82e57ca45806c"
            },
            {
              "url": "https://git.kernel.org/stable/c/c3720b04df84b5459050ae4e03ec7d545652f897"
            },
            {
              "url": "https://git.kernel.org/stable/c/e905a0fca7bff0855d312c16f71e60e1773b393e"
            },
            {
              "url": "https://git.kernel.org/stable/c/62d8f4c5454dd39aded4f343720d1c5a1803cfef"
            },
            {
              "url": "https://git.kernel.org/stable/c/5b9778e1fe715700993ce436c152dc3b7df0b490"
            },
            {
              "url": "https://git.kernel.org/stable/c/2240fed37afbcdb5e8b627bc7ad986891100e05d"
            }
          ],
          "title": "USB: hub: Ignore non-compliant devices with too many configs or interfaces",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2025-21776",
        "datePublished": "2025-02-27T02:18:21.503Z",
        "dateReserved": "2024-12-29T08:45:45.763Z",
        "dateUpdated": "2026-05-12T12:03:52.412Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-21762 (GCVE-0-2025-21762)

    Vulnerability from nvd – Published: 2025-02-27 02:18 – Updated: 2026-08-05 11:54
    VLAI
    Title
    arp: use RCU protection in arp_xmit()
    Summary
    In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() can be called without RTNL or RCU protection. Use RCU protection to avoid potential UAF.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-27 17:57 UTC
    CWE
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < 10f555e3f573d004ae9d89b3276abb58c4ede5c3 (git)
    Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < 307cd1e2d3cb1cbc6c40c679cada6d7168b18431 (git)
    Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < d9366ac2f956a1948b68c0500f84a3462ff2ed8a (git)
    Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < f189654459423d4d48bef2d120b4bfba559e6039 (git)
    Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < e9f4dee534eb1b225b0a120395ad9bc2afe164d3 (git)
    Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < 01d1b5c9abcaff29a43f1d17a19c33eec92c7dbe (git)
    Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < 2c331718d3389b6c5f6855078ab7171849e016bd (git)
    Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < a42b69f692165ec39db42d595f4f65a4c8f42e44 (git)
    Create a notification for this product.
    Linux Linux Affected: 4.4
    Unaffected: 0 , < 4.4 (semver)
    Unaffected: 5.4.291 , ≤ 5.4.* (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.129 , ≤ 6.1.* (semver)
    Unaffected: 6.6.79 , ≤ 6.6.* (semver)
    Unaffected: 6.12.16 , ≤ 6.12.* (semver)
    Unaffected: 6.13.4 , ≤ 6.13.* (semver)
    Unaffected: 6.14 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-21762",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-27T17:57:30.024595Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-27T18:02:27.083Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:37:11.540Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:03:43.118Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/ipv4/arp.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "10f555e3f573d004ae9d89b3276abb58c4ede5c3",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                },
                {
                  "lessThan": "307cd1e2d3cb1cbc6c40c679cada6d7168b18431",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                },
                {
                  "lessThan": "d9366ac2f956a1948b68c0500f84a3462ff2ed8a",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                },
                {
                  "lessThan": "f189654459423d4d48bef2d120b4bfba559e6039",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                },
                {
                  "lessThan": "e9f4dee534eb1b225b0a120395ad9bc2afe164d3",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                },
                {
                  "lessThan": "01d1b5c9abcaff29a43f1d17a19c33eec92c7dbe",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                },
                {
                  "lessThan": "2c331718d3389b6c5f6855078ab7171849e016bd",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                },
                {
                  "lessThan": "a42b69f692165ec39db42d595f4f65a4c8f42e44",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/ipv4/arp.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.4"
                },
                {
                  "lessThan": "4.4",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.291",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.129",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.79",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.16",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.13.*",
                  "status": "unaffected",
                  "version": "6.13.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.14",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.291",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.129",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.79",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.16",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13.4",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.14",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\narp: use RCU protection in arp_xmit()\n\narp_xmit() can be called without RTNL or RCU protection.\n\nUse RCU protection to avoid potential UAF."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:N - The unprotected `arp_xmit()` calls are driven by the neighbour-resolution path (`neigh_timer_handler` \u2192 `neigh_probe` \u2192 `arp_solicit`), which a remote off-link attacker triggers at will by sending traffic to a Linux router/gateway that must resolve on-link next hops, as well as by ARP frames processed in `arp_process()`/bridge neigh-suppression. The vulnerable code is bound to the network stack and reachable from remotely originated packets, so Network is the correct and higher-severity classification.\nAC:H - The attacker fully controls and can sustain the ARP-transmit side of the race, but the other side \u2014 a `struct net` being freed via `cleanup_net()` or a device migrating namespaces \u2014 is background system activity the network attacker cannot command. Because that condition lies outside attacker control, complexity is High.\nPR:N - There is no capability check, credential check, or authentication gate anywhere on the path from packet receipt/neighbour resolution to `arp_xmit()`; ARP solicitation and reply generation happen unconditionally in softirq context. An entirely unauthenticated attacker reaches the vulnerable code.\nUI:N - The attacker\u0027s own packets cause the kernel to emit ARP and execute the vulnerable code; no victim must mount a filesystem, open a file, or take any other action.\nS:U - The use-after-free of `struct net` and the resulting corruption stay entirely within the kernel\u0027s own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - A use-after-free of `struct net` lets `nf_hook()` read `net-\u003enf.hooks_arp[]` and every ARP-family hook read `state-\u003enet` out of freed, potentially reallocated slab memory. Per kernel guidance a UAF gives the attacker control over the freed object\u0027s contents and thus an arbitrary kernel-memory read primitive.\nI:H - The stale `net` yields a `hook_head` pointer from freed memory, and `nf_hook_slow()` then performs an indirect call through `e-\u003ehooks[s].hook` \u2014 a direct function-pointer hijack primitive if the netns slab is reallocated with sprayed data. Hooks also write through `state-\u003enet`, corrupting reused kernel objects.\nA:H - Dereferencing a freed `struct net` and calling through a garbage `nf_hook_entries` reliably oopses or panics the kernel, and is a KASAN-reportable memory-safety violation that panics on hardened configurations. Any such kernel crash is scored High."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:54:15.248Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/10f555e3f573d004ae9d89b3276abb58c4ede5c3"
            },
            {
              "url": "https://git.kernel.org/stable/c/307cd1e2d3cb1cbc6c40c679cada6d7168b18431"
            },
            {
              "url": "https://git.kernel.org/stable/c/d9366ac2f956a1948b68c0500f84a3462ff2ed8a"
            },
            {
              "url": "https://git.kernel.org/stable/c/f189654459423d4d48bef2d120b4bfba559e6039"
            },
            {
              "url": "https://git.kernel.org/stable/c/e9f4dee534eb1b225b0a120395ad9bc2afe164d3"
            },
            {
              "url": "https://git.kernel.org/stable/c/01d1b5c9abcaff29a43f1d17a19c33eec92c7dbe"
            },
            {
              "url": "https://git.kernel.org/stable/c/2c331718d3389b6c5f6855078ab7171849e016bd"
            },
            {
              "url": "https://git.kernel.org/stable/c/a42b69f692165ec39db42d595f4f65a4c8f42e44"
            }
          ],
          "title": "arp: use RCU protection in arp_xmit()",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2025-21762",
        "datePublished": "2025-02-27T02:18:14.600Z",
        "dateReserved": "2024-12-29T08:45:45.761Z",
        "dateUpdated": "2026-08-05T11:54:15.248Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-58005 (GCVE-0-2024-58005)

    Vulnerability from nvd – Published: 2025-02-27 02:12 – Updated: 2026-07-14 12:38
    VLAI
    Title
    tpm: Change to kvalloc() in eventlog/acpi.c
    Summary
    In the Linux kernel, the following vulnerability has been resolved: tpm: Change to kvalloc() in eventlog/acpi.c The following failure was reported on HPE ProLiant D320: [ 10.693310][ T1] tpm_tis STM0925:00: 2.0 TPM (device-id 0x3, rev-id 0) [ 10.848132][ T1] ------------[ cut here ]------------ [ 10.853559][ T1] WARNING: CPU: 59 PID: 1 at mm/page_alloc.c:4727 __alloc_pages_noprof+0x2ca/0x330 [ 10.862827][ T1] Modules linked in: [ 10.866671][ T1] CPU: 59 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.0-lp155.2.g52785e2-default #1 openSUSE Tumbleweed (unreleased) 588cd98293a7c9eba9013378d807364c088c9375 [ 10.882741][ T1] Hardware name: HPE ProLiant DL320 Gen12/ProLiant DL320 Gen12, BIOS 1.20 10/28/2024 [ 10.892170][ T1] RIP: 0010:__alloc_pages_noprof+0x2ca/0x330 [ 10.898103][ T1] Code: 24 08 e9 4a fe ff ff e8 34 36 fa ff e9 88 fe ff ff 83 fe 0a 0f 86 b3 fd ff ff 80 3d 01 e7 ce 01 00 75 09 c6 05 f8 e6 ce 01 01 <0f> 0b 45 31 ff e9 e5 fe ff ff f7 c2 00 00 08 00 75 42 89 d9 80 e1 [ 10.917750][ T1] RSP: 0000:ffffb7cf40077980 EFLAGS: 00010246 [ 10.923777][ T1] RAX: 0000000000000000 RBX: 0000000000040cc0 RCX: 0000000000000000 [ 10.931727][ T1] RDX: 0000000000000000 RSI: 000000000000000c RDI: 0000000000040cc0 The above transcript shows that ACPI pointed a 16 MiB buffer for the log events because RSI maps to the 'order' parameter of __alloc_pages_noprof(). Address the bug by moving from devm_kmalloc() to devm_add_action() and kvmalloc() and devm_add_action().
    Severity
    No CVSS data available.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 55a82ab3181be039c6440d3f2f69260ad6fe2988 , < a676c0401de59548a5bc1b7aaf98f556ae8ea6db (git)
    Affected: 55a82ab3181be039c6440d3f2f69260ad6fe2988 , < 0621d2599d6e02d05c85d6bbd58eaea2f15b3503 (git)
    Affected: 55a82ab3181be039c6440d3f2f69260ad6fe2988 , < 77779d1258a287f2c5c2c6aeae203e0996209c77 (git)
    Affected: 55a82ab3181be039c6440d3f2f69260ad6fe2988 , < 50365a6304a57266e8f4d3078060743c3b7a1e0d (git)
    Affected: 55a82ab3181be039c6440d3f2f69260ad6fe2988 , < 422d7f4e8d817be467986589c7968d3ea402f7da (git)
    Affected: 55a82ab3181be039c6440d3f2f69260ad6fe2988 , < 4c8bfe643bbd00b04ee8f9545ef33bf6a68c38db (git)
    Affected: 55a82ab3181be039c6440d3f2f69260ad6fe2988 , < a3a860bc0fd6c07332e4911cf9a238d20de90173 (git)
    Create a notification for this product.
    Linux Linux Affected: 2.6.16
    Unaffected: 0 , < 2.6.16 (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.130 , ≤ 6.1.* (semver)
    Unaffected: 6.6.78 , ≤ 6.6.* (semver)
    Unaffected: 6.12.14 , ≤ 6.12.* (semver)
    Unaffected: 6.13.3 , ≤ 6.13.* (semver)
    Unaffected: 6.14 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.5 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP Affected: V3.1.5 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.5 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:33:18.687Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-14T12:38:49.969Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/char/tpm/eventlog/acpi.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "a676c0401de59548a5bc1b7aaf98f556ae8ea6db",
                  "status": "affected",
                  "version": "55a82ab3181be039c6440d3f2f69260ad6fe2988",
                  "versionType": "git"
                },
                {
                  "lessThan": "0621d2599d6e02d05c85d6bbd58eaea2f15b3503",
                  "status": "affected",
                  "version": "55a82ab3181be039c6440d3f2f69260ad6fe2988",
                  "versionType": "git"
                },
                {
                  "lessThan": "77779d1258a287f2c5c2c6aeae203e0996209c77",
                  "status": "affected",
                  "version": "55a82ab3181be039c6440d3f2f69260ad6fe2988",
                  "versionType": "git"
                },
                {
                  "lessThan": "50365a6304a57266e8f4d3078060743c3b7a1e0d",
                  "status": "affected",
                  "version": "55a82ab3181be039c6440d3f2f69260ad6fe2988",
                  "versionType": "git"
                },
                {
                  "lessThan": "422d7f4e8d817be467986589c7968d3ea402f7da",
                  "status": "affected",
                  "version": "55a82ab3181be039c6440d3f2f69260ad6fe2988",
                  "versionType": "git"
                },
                {
                  "lessThan": "4c8bfe643bbd00b04ee8f9545ef33bf6a68c38db",
                  "status": "affected",
                  "version": "55a82ab3181be039c6440d3f2f69260ad6fe2988",
                  "versionType": "git"
                },
                {
                  "lessThan": "a3a860bc0fd6c07332e4911cf9a238d20de90173",
                  "status": "affected",
                  "version": "55a82ab3181be039c6440d3f2f69260ad6fe2988",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/char/tpm/eventlog/acpi.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.6.16"
                },
                {
                  "lessThan": "2.6.16",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.130",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.78",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.14",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.13.*",
                  "status": "unaffected",
                  "version": "6.13.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.14",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "2.6.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "2.6.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.130",
                      "versionStartIncluding": "2.6.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.78",
                      "versionStartIncluding": "2.6.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.14",
                      "versionStartIncluding": "2.6.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13.3",
                      "versionStartIncluding": "2.6.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.14",
                      "versionStartIncluding": "2.6.16",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: Change to kvalloc() in eventlog/acpi.c\n\nThe following failure was reported on HPE ProLiant D320:\n\n[   10.693310][    T1] tpm_tis STM0925:00: 2.0 TPM (device-id 0x3, rev-id 0)\n[   10.848132][    T1] ------------[ cut here ]------------\n[   10.853559][    T1] WARNING: CPU: 59 PID: 1 at mm/page_alloc.c:4727 __alloc_pages_noprof+0x2ca/0x330\n[   10.862827][    T1] Modules linked in:\n[   10.866671][    T1] CPU: 59 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.0-lp155.2.g52785e2-default #1 openSUSE Tumbleweed (unreleased) 588cd98293a7c9eba9013378d807364c088c9375\n[   10.882741][    T1] Hardware name: HPE ProLiant DL320 Gen12/ProLiant DL320 Gen12, BIOS 1.20 10/28/2024\n[   10.892170][    T1] RIP: 0010:__alloc_pages_noprof+0x2ca/0x330\n[   10.898103][    T1] Code: 24 08 e9 4a fe ff ff e8 34 36 fa ff e9 88 fe ff ff 83 fe 0a 0f 86 b3 fd ff ff 80 3d 01 e7 ce 01 00 75 09 c6 05 f8 e6 ce 01 01 \u003c0f\u003e 0b 45 31 ff e9 e5 fe ff ff f7 c2 00 00 08 00 75 42 89 d9 80 e1\n[   10.917750][    T1] RSP: 0000:ffffb7cf40077980 EFLAGS: 00010246\n[   10.923777][    T1] RAX: 0000000000000000 RBX: 0000000000040cc0 RCX: 0000000000000000\n[   10.931727][    T1] RDX: 0000000000000000 RSI: 000000000000000c RDI: 0000000000040cc0\n\nThe above transcript shows that ACPI pointed a 16 MiB buffer for the log\nevents because RSI maps to the \u0027order\u0027 parameter of __alloc_pages_noprof().\nAddress the bug by moving from devm_kmalloc() to devm_add_action() and\nkvmalloc() and devm_add_action()."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T21:01:57.391Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/a676c0401de59548a5bc1b7aaf98f556ae8ea6db"
            },
            {
              "url": "https://git.kernel.org/stable/c/0621d2599d6e02d05c85d6bbd58eaea2f15b3503"
            },
            {
              "url": "https://git.kernel.org/stable/c/77779d1258a287f2c5c2c6aeae203e0996209c77"
            },
            {
              "url": "https://git.kernel.org/stable/c/50365a6304a57266e8f4d3078060743c3b7a1e0d"
            },
            {
              "url": "https://git.kernel.org/stable/c/422d7f4e8d817be467986589c7968d3ea402f7da"
            },
            {
              "url": "https://git.kernel.org/stable/c/4c8bfe643bbd00b04ee8f9545ef33bf6a68c38db"
            },
            {
              "url": "https://git.kernel.org/stable/c/a3a860bc0fd6c07332e4911cf9a238d20de90173"
            }
          ],
          "title": "tpm: Change to kvalloc() in eventlog/acpi.c",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-58005",
        "datePublished": "2025-02-27T02:12:02.232Z",
        "dateReserved": "2025-02-27T02:10:48.226Z",
        "dateUpdated": "2026-07-14T12:38:49.969Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-57981 (GCVE-0-2024-57981)

    Vulnerability from nvd – Published: 2025-02-27 02:07 – Updated: 2026-05-12 12:01
    VLAI
    Title
    usb: xhci: Fix NULL pointer dereference on certain command aborts
    Summary
    In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix NULL pointer dereference on certain command aborts If a command is queued to the final usable TRB of a ring segment, the enqueue pointer is advanced to the subsequent link TRB and no further. If the command is later aborted, when the abort completion is handled the dequeue pointer is advanced to the first TRB of the next segment. If no further commands are queued, xhci_handle_stopped_cmd_ring() sees the ring pointers unequal and assumes that there is a pending command, so it calls xhci_mod_cmd_timer() which crashes if cur_cmd was NULL. Don't attempt timer setup if cur_cmd is NULL. The subsequent doorbell ring likely is unnecessary too, but it's harmless. Leave it alone. This is probably Bug 219532, but no confirmation has been received. The issue has been independently reproduced and confirmed fixed using a USB MCU programmed to NAK the Status stage of SET_ADDRESS forever. Everything continued working normally after several prevented crashes.
    Severity
    No CVSS data available.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: c311e391a7efd101250c0e123286709b7e736249 , < fd8bfaeba4a85b14427899adec0efb3954300653 (git)
    Affected: c311e391a7efd101250c0e123286709b7e736249 , < b44253956407046e5907d4d72c8fa5b93ae94485 (git)
    Affected: c311e391a7efd101250c0e123286709b7e736249 , < cf30300a216a4f8dce94e11781a866a09d4b50d4 (git)
    Affected: c311e391a7efd101250c0e123286709b7e736249 , < 4ff18870af793ce2034a6ad746e91d0a3d985b88 (git)
    Affected: c311e391a7efd101250c0e123286709b7e736249 , < b649f0d5bc256f691c7d234c3986685d54053de1 (git)
    Affected: c311e391a7efd101250c0e123286709b7e736249 , < ae069cd2ba09a2bd6a87a68c59ef0b7ea39cd641 (git)
    Affected: c311e391a7efd101250c0e123286709b7e736249 , < 0ce5c0dac768be14afe2426101b568a0f66bfc4d (git)
    Affected: c311e391a7efd101250c0e123286709b7e736249 , < 1e0a19912adb68a4b2b74fd77001c96cd83eb073 (git)
    Create a notification for this product.
    Linux Linux Affected: 3.16
    Unaffected: 0 , < 3.16 (semver)
    Unaffected: 5.4.291 , ≤ 5.4.* (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.129 , ≤ 6.1.* (semver)
    Unaffected: 6.6.76 , ≤ 6.6.* (semver)
    Unaffected: 6.12.13 , ≤ 6.12.* (semver)
    Unaffected: 6.13.2 , ≤ 6.13.* (semver)
    Unaffected: 6.14 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:33:02.039Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:01:46.491Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/usb/host/xhci-ring.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "fd8bfaeba4a85b14427899adec0efb3954300653",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                },
                {
                  "lessThan": "b44253956407046e5907d4d72c8fa5b93ae94485",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                },
                {
                  "lessThan": "cf30300a216a4f8dce94e11781a866a09d4b50d4",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                },
                {
                  "lessThan": "4ff18870af793ce2034a6ad746e91d0a3d985b88",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                },
                {
                  "lessThan": "b649f0d5bc256f691c7d234c3986685d54053de1",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                },
                {
                  "lessThan": "ae069cd2ba09a2bd6a87a68c59ef0b7ea39cd641",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                },
                {
                  "lessThan": "0ce5c0dac768be14afe2426101b568a0f66bfc4d",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                },
                {
                  "lessThan": "1e0a19912adb68a4b2b74fd77001c96cd83eb073",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/usb/host/xhci-ring.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.16"
                },
                {
                  "lessThan": "3.16",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.291",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.129",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.76",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.13",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.13.*",
                  "status": "unaffected",
                  "version": "6.13.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.14",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.291",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.129",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.76",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.13",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13.2",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.14",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: Fix NULL pointer dereference on certain command aborts\n\nIf a command is queued to the final usable TRB of a ring segment, the\nenqueue pointer is advanced to the subsequent link TRB and no further.\nIf the command is later aborted, when the abort completion is handled\nthe dequeue pointer is advanced to the first TRB of the next segment.\n\nIf no further commands are queued, xhci_handle_stopped_cmd_ring() sees\nthe ring pointers unequal and assumes that there is a pending command,\nso it calls xhci_mod_cmd_timer() which crashes if cur_cmd was NULL.\n\nDon\u0027t attempt timer setup if cur_cmd is NULL. The subsequent doorbell\nring likely is unnecessary too, but it\u0027s harmless. Leave it alone.\n\nThis is probably Bug 219532, but no confirmation has been received.\n\nThe issue has been independently reproduced and confirmed fixed using\na USB MCU programmed to NAK the Status stage of SET_ADDRESS forever.\nEverything continued working normally after several prevented crashes."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T21:01:29.822Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/fd8bfaeba4a85b14427899adec0efb3954300653"
            },
            {
              "url": "https://git.kernel.org/stable/c/b44253956407046e5907d4d72c8fa5b93ae94485"
            },
            {
              "url": "https://git.kernel.org/stable/c/cf30300a216a4f8dce94e11781a866a09d4b50d4"
            },
            {
              "url": "https://git.kernel.org/stable/c/4ff18870af793ce2034a6ad746e91d0a3d985b88"
            },
            {
              "url": "https://git.kernel.org/stable/c/b649f0d5bc256f691c7d234c3986685d54053de1"
            },
            {
              "url": "https://git.kernel.org/stable/c/ae069cd2ba09a2bd6a87a68c59ef0b7ea39cd641"
            },
            {
              "url": "https://git.kernel.org/stable/c/0ce5c0dac768be14afe2426101b568a0f66bfc4d"
            },
            {
              "url": "https://git.kernel.org/stable/c/1e0a19912adb68a4b2b74fd77001c96cd83eb073"
            }
          ],
          "title": "usb: xhci: Fix NULL pointer dereference on certain command aborts",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-57981",
        "datePublished": "2025-02-27T02:07:07.489Z",
        "dateReserved": "2025-02-27T02:04:28.913Z",
        "dateUpdated": "2026-05-12T12:01:46.491Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-21678 (GCVE-0-2025-21678)

    Vulnerability from nvd – Published: 2025-01-31 11:25 – Updated: 2026-08-05 11:53
    VLAI
    Title
    gtp: Destroy device along with udp socket's netns dismantle.
    Summary
    In the Linux kernel, the following vulnerability has been resolved: gtp: Destroy device along with udp socket's netns dismantle. gtp_newlink() links the device to a list in dev_net(dev) instead of src_net, where a udp tunnel socket is created. Even when src_net is removed, the device stays alive on dev_net(dev). Then, removing src_net triggers the splat below. [0] In this example, gtp0 is created in ns2, and the udp socket is created in ns1. ip netns add ns1 ip netns add ns2 ip -n ns1 link add netns ns2 name gtp0 type gtp role sgsn ip netns del ns1 Let's link the device to the socket's netns instead. Now, gtp_net_exit_batch_rtnl() needs another netdev iteration to remove all gtp devices in the netns. [0]: ref_tracker: net notrefcnt@000000003d6e7d05 has 1/2 users at sk_alloc (./include/net/net_namespace.h:345 net/core/sock.c:2236) inet_create (net/ipv4/af_inet.c:326 net/ipv4/af_inet.c:252) __sock_create (net/socket.c:1558) udp_sock_create4 (net/ipv4/udp_tunnel_core.c:18) gtp_create_sock (./include/net/udp_tunnel.h:59 drivers/net/gtp.c:1423) gtp_create_sockets (drivers/net/gtp.c:1447) gtp_newlink (drivers/net/gtp.c:1507) rtnl_newlink (net/core/rtnetlink.c:3786 net/core/rtnetlink.c:3897 net/core/rtnetlink.c:4012) rtnetlink_rcv_msg (net/core/rtnetlink.c:6922) netlink_rcv_skb (net/netlink/af_netlink.c:2542) netlink_unicast (net/netlink/af_netlink.c:1321 net/netlink/af_netlink.c:1347) netlink_sendmsg (net/netlink/af_netlink.c:1891) ____sys_sendmsg (net/socket.c:711 net/socket.c:726 net/socket.c:2583) ___sys_sendmsg (net/socket.c:2639) __sys_sendmsg (net/socket.c:2669) do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) WARNING: CPU: 1 PID: 60 at lib/ref_tracker.c:179 ref_tracker_dir_exit (lib/ref_tracker.c:179) Modules linked in: CPU: 1 UID: 0 PID: 60 Comm: kworker/u16:2 Not tainted 6.13.0-rc5-00147-g4c1224501e9d #5 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 Workqueue: netns cleanup_net RIP: 0010:ref_tracker_dir_exit (lib/ref_tracker.c:179) Code: 00 00 00 fc ff df 4d 8b 26 49 bd 00 01 00 00 00 00 ad de 4c 39 f5 0f 85 df 00 00 00 48 8b 74 24 08 48 89 df e8 a5 cc 12 02 90 <0f> 0b 90 48 8d 6b 44 be 04 00 00 00 48 89 ef e8 80 de 67 ff 48 89 RSP: 0018:ff11000009a07b60 EFLAGS: 00010286 RAX: 0000000000002bd3 RBX: ff1100000f4e1aa0 RCX: 1ffffffff0e40ac6 RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff8423ee3c RBP: ff1100000f4e1af0 R08: 0000000000000001 R09: fffffbfff0e395ae R10: 0000000000000001 R11: 0000000000036001 R12: ff1100000f4e1af0 R13: dead000000000100 R14: ff1100000f4e1af0 R15: dffffc0000000000 FS: 0000000000000000(0000) GS:ff1100006ce80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f9b2464bd98 CR3: 0000000005286005 CR4: 0000000000771ef0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400 PKRU: 55555554 Call Trace: <TASK> ? __warn (kernel/panic.c:748) ? ref_tracker_dir_exit (lib/ref_tracker.c:179) ? report_bug (lib/bug.c:201 lib/bug.c:219) ? handle_bug (arch/x86/kernel/traps.c:285) ? exc_invalid_op (arch/x86/kernel/traps.c:309 (discriminator 1)) ? asm_exc_invalid_op (./arch/x86/include/asm/idtentry.h:621) ? _raw_spin_unlock_irqrestore (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:97 ./arch/x86/include/asm/irqflags.h:155 ./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194) ? ref_tracker_dir_exit (lib/ref_tracker.c:179) ? __pfx_ref_tracker_dir_exit (lib/ref_tracker.c:158) ? kfree (mm/slub.c:4613 mm/slub.c:4761) net_free (net/core/net_namespace.c:476 net/core/net_namespace.c:467) cleanup_net (net/core/net_namespace.c:664 (discriminator 3)) process_one_work (kernel/workqueue.c:3229) worker_thread (kernel/workqueue.c:3304 kernel/workqueue.c:3391 ---truncated---
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 459aa660eb1d8ce67080da1983bb81d716aa5a69 , < c986380c1d5274c4d5e935addc807d6791cc23eb (git)
    Affected: 459aa660eb1d8ce67080da1983bb81d716aa5a69 , < 5f1678346109ff3a6d229d33437fcba3cce9209d (git)
    Affected: 459aa660eb1d8ce67080da1983bb81d716aa5a69 , < 036f8d814a2cd11ee8ef62b8f3e7ce5dec0ee4f3 (git)
    Affected: 459aa660eb1d8ce67080da1983bb81d716aa5a69 , < efec287cbac92ac6ee8312a89221854760e13b34 (git)
    Affected: 459aa660eb1d8ce67080da1983bb81d716aa5a69 , < bb11f992f5a475bc68ef959f17a55306f0328495 (git)
    Affected: 459aa660eb1d8ce67080da1983bb81d716aa5a69 , < 86f73d4ab2f27deeff22ba9336ad103d94f12ac7 (git)
    Affected: 459aa660eb1d8ce67080da1983bb81d716aa5a69 , < eb28fd76c0a08a47b470677c6cef9dd1c60e92d1 (git)
    Create a notification for this product.
    Linux Linux Affected: 4.7
    Unaffected: 0 , < 4.7 (semver)
    Unaffected: 5.4.290 , ≤ 5.4.* (semver)
    Unaffected: 5.10.234 , ≤ 5.10.* (semver)
    Unaffected: 5.15.177 , ≤ 5.15.* (semver)
    Unaffected: 6.1.127 , ≤ 6.1.* (semver)
    Unaffected: 6.6.74 , ≤ 6.6.* (semver)
    Unaffected: 6.12.11 , ≤ 6.12.* (semver)
    Unaffected: 6.13 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:58:55.888Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:03:10.577Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/net/gtp.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "c986380c1d5274c4d5e935addc807d6791cc23eb",
                  "status": "affected",
                  "version": "459aa660eb1d8ce67080da1983bb81d716aa5a69",
                  "versionType": "git"
                },
                {
                  "lessThan": "5f1678346109ff3a6d229d33437fcba3cce9209d",
                  "status": "affected",
                  "version": "459aa660eb1d8ce67080da1983bb81d716aa5a69",
                  "versionType": "git"
                },
                {
                  "lessThan": "036f8d814a2cd11ee8ef62b8f3e7ce5dec0ee4f3",
                  "status": "affected",
                  "version": "459aa660eb1d8ce67080da1983bb81d716aa5a69",
                  "versionType": "git"
                },
                {
                  "lessThan": "efec287cbac92ac6ee8312a89221854760e13b34",
                  "status": "affected",
                  "version": "459aa660eb1d8ce67080da1983bb81d716aa5a69",
                  "versionType": "git"
                },
                {
                  "lessThan": "bb11f992f5a475bc68ef959f17a55306f0328495",
                  "status": "affected",
                  "version": "459aa660eb1d8ce67080da1983bb81d716aa5a69",
                  "versionType": "git"
                },
                {
                  "lessThan": "86f73d4ab2f27deeff22ba9336ad103d94f12ac7",
                  "status": "affected",
                  "version": "459aa660eb1d8ce67080da1983bb81d716aa5a69",
                  "versionType": "git"
                },
                {
                  "lessThan": "eb28fd76c0a08a47b470677c6cef9dd1c60e92d1",
                  "status": "affected",
                  "version": "459aa660eb1d8ce67080da1983bb81d716aa5a69",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/net/gtp.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.7"
                },
                {
                  "lessThan": "4.7",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.290",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.234",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.177",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.127",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.74",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.11",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.13",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.290",
                      "versionStartIncluding": "4.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.234",
                      "versionStartIncluding": "4.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.177",
                      "versionStartIncluding": "4.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.127",
                      "versionStartIncluding": "4.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.74",
                      "versionStartIncluding": "4.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.11",
                      "versionStartIncluding": "4.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13",
                      "versionStartIncluding": "4.7",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: Destroy device along with udp socket\u0027s netns dismantle.\n\ngtp_newlink() links the device to a list in dev_net(dev) instead of\nsrc_net, where a udp tunnel socket is created.\n\nEven when src_net is removed, the device stays alive on dev_net(dev).\nThen, removing src_net triggers the splat below. [0]\n\nIn this example, gtp0 is created in ns2, and the udp socket is created\nin ns1.\n\n  ip netns add ns1\n  ip netns add ns2\n  ip -n ns1 link add netns ns2 name gtp0 type gtp role sgsn\n  ip netns del ns1\n\nLet\u0027s link the device to the socket\u0027s netns instead.\n\nNow, gtp_net_exit_batch_rtnl() needs another netdev iteration to remove\nall gtp devices in the netns.\n\n[0]:\nref_tracker: net notrefcnt@000000003d6e7d05 has 1/2 users at\n     sk_alloc (./include/net/net_namespace.h:345 net/core/sock.c:2236)\n     inet_create (net/ipv4/af_inet.c:326 net/ipv4/af_inet.c:252)\n     __sock_create (net/socket.c:1558)\n     udp_sock_create4 (net/ipv4/udp_tunnel_core.c:18)\n     gtp_create_sock (./include/net/udp_tunnel.h:59 drivers/net/gtp.c:1423)\n     gtp_create_sockets (drivers/net/gtp.c:1447)\n     gtp_newlink (drivers/net/gtp.c:1507)\n     rtnl_newlink (net/core/rtnetlink.c:3786 net/core/rtnetlink.c:3897 net/core/rtnetlink.c:4012)\n     rtnetlink_rcv_msg (net/core/rtnetlink.c:6922)\n     netlink_rcv_skb (net/netlink/af_netlink.c:2542)\n     netlink_unicast (net/netlink/af_netlink.c:1321 net/netlink/af_netlink.c:1347)\n     netlink_sendmsg (net/netlink/af_netlink.c:1891)\n     ____sys_sendmsg (net/socket.c:711 net/socket.c:726 net/socket.c:2583)\n     ___sys_sendmsg (net/socket.c:2639)\n     __sys_sendmsg (net/socket.c:2669)\n     do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83)\n\nWARNING: CPU: 1 PID: 60 at lib/ref_tracker.c:179 ref_tracker_dir_exit (lib/ref_tracker.c:179)\nModules linked in:\nCPU: 1 UID: 0 PID: 60 Comm: kworker/u16:2 Not tainted 6.13.0-rc5-00147-g4c1224501e9d #5\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\nWorkqueue: netns cleanup_net\nRIP: 0010:ref_tracker_dir_exit (lib/ref_tracker.c:179)\nCode: 00 00 00 fc ff df 4d 8b 26 49 bd 00 01 00 00 00 00 ad de 4c 39 f5 0f 85 df 00 00 00 48 8b 74 24 08 48 89 df e8 a5 cc 12 02 90 \u003c0f\u003e 0b 90 48 8d 6b 44 be 04 00 00 00 48 89 ef e8 80 de 67 ff 48 89\nRSP: 0018:ff11000009a07b60 EFLAGS: 00010286\nRAX: 0000000000002bd3 RBX: ff1100000f4e1aa0 RCX: 1ffffffff0e40ac6\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff8423ee3c\nRBP: ff1100000f4e1af0 R08: 0000000000000001 R09: fffffbfff0e395ae\nR10: 0000000000000001 R11: 0000000000036001 R12: ff1100000f4e1af0\nR13: dead000000000100 R14: ff1100000f4e1af0 R15: dffffc0000000000\nFS:  0000000000000000(0000) GS:ff1100006ce80000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f9b2464bd98 CR3: 0000000005286005 CR4: 0000000000771ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \u003cTASK\u003e\n ? __warn (kernel/panic.c:748)\n ? ref_tracker_dir_exit (lib/ref_tracker.c:179)\n ? report_bug (lib/bug.c:201 lib/bug.c:219)\n ? handle_bug (arch/x86/kernel/traps.c:285)\n ? exc_invalid_op (arch/x86/kernel/traps.c:309 (discriminator 1))\n ? asm_exc_invalid_op (./arch/x86/include/asm/idtentry.h:621)\n ? _raw_spin_unlock_irqrestore (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:97 ./arch/x86/include/asm/irqflags.h:155 ./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194)\n ? ref_tracker_dir_exit (lib/ref_tracker.c:179)\n ? __pfx_ref_tracker_dir_exit (lib/ref_tracker.c:158)\n ? kfree (mm/slub.c:4613 mm/slub.c:4761)\n net_free (net/core/net_namespace.c:476 net/core/net_namespace.c:467)\n cleanup_net (net/core/net_namespace.c:664 (discriminator 3))\n process_one_work (kernel/workqueue.c:3229)\n worker_thread (kernel/workqueue.c:3304 kernel/workqueue.c:3391\n---truncated---"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The vulnerability is triggered entirely through local syscalls \u2014 an RTM_NEWLINK netlink message creating a GTP device with the link in a different netns than the netlink socket, followed by teardown of that netns. No remote packet processing is involved in reaching the bug.\nAC:L - The four-command reproducer in the commit message triggers it deterministically with no race and no dependence on uncontrolled memory layout; reoccupying the freed struct net is done by simply calling unshare(CLONE_NEWNET), which is fully under attacker control.\nPR:L - Both gates on the path (netlink_net_capable and rtnl_link_get_net_capable) check CAP_NET_ADMIN against net-\u003euser_ns, which an unprivileged user obtains for netns it creates via `unshare -Urn`; the gtp module is autoloaded on demand from the same path.\nUI:N - The attacker performs every step \u2014 creating the namespaces, creating the GTP link, and destroying the socket\u0027s namespace \u2014 with no action required from any other user.\nS:U - The dangling struct net pointer and the resulting corruption are confined to the kernel\u0027s own security authority; there is no hypervisor, IOMMU, or other authority boundary crossed.\nC:H - This is a use-after-free of struct net whose freed slab object the attacker can deterministically reoccupy, so subsequent reads through gtp-\u003enet and sock_net(sk) return attacker-groomed contents and route/socket lookups are performed against a foreign namespace\u0027s tables, enabling information disclosure.\nI:H - The teardown path performs __netns_tracker_free() on the freed net \u2014 a spinlock acquisition and list_del() into freed memory \u2014 giving a write-after-free/unlink primitive, and the aliased netns allows packets to be routed and sockets to be hashed into a namespace the attacker does not own.\nA:H - The bug reliably produces a ref_tracker_dir_exit() WARNING splat in cleanup_net (a panic under panic_on_warn), and the subsequent use-after-free of struct net causes kernel oopses/panics on device teardown or transmit."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:53:34.427Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/c986380c1d5274c4d5e935addc807d6791cc23eb"
            },
            {
              "url": "https://git.kernel.org/stable/c/5f1678346109ff3a6d229d33437fcba3cce9209d"
            },
            {
              "url": "https://git.kernel.org/stable/c/036f8d814a2cd11ee8ef62b8f3e7ce5dec0ee4f3"
            },
            {
              "url": "https://git.kernel.org/stable/c/efec287cbac92ac6ee8312a89221854760e13b34"
            },
            {
              "url": "https://git.kernel.org/stable/c/bb11f992f5a475bc68ef959f17a55306f0328495"
            },
            {
              "url": "https://git.kernel.org/stable/c/86f73d4ab2f27deeff22ba9336ad103d94f12ac7"
            },
            {
              "url": "https://git.kernel.org/stable/c/eb28fd76c0a08a47b470677c6cef9dd1c60e92d1"
            }
          ],
          "title": "gtp: Destroy device along with udp socket\u0027s netns dismantle.",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2025-21678",
        "datePublished": "2025-01-31T11:25:39.500Z",
        "dateReserved": "2024-12-29T08:45:45.738Z",
        "dateUpdated": "2026-08-05T11:53:34.427Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-57940 (GCVE-0-2024-57940)

    Vulnerability from nvd – Published: 2025-01-21 12:18 – Updated: 2026-05-12 12:01
    VLAI
    Title
    exfat: fix the infinite loop in exfat_readdir()
    Summary
    In the Linux kernel, the following vulnerability has been resolved: exfat: fix the infinite loop in exfat_readdir() If the file system is corrupted so that a cluster is linked to itself in the cluster chain, and there is an unused directory entry in the cluster, 'dentry' will not be incremented, causing condition 'dentry < max_dentries' unable to prevent an infinite loop. This infinite loop causes s_lock not to be released, and other tasks will hang, such as exfat_sync_fs(). This commit stops traversing the cluster chain when there is unused directory entry in the cluster to avoid this infinite loop.
    Severity
    No CVSS data available.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: ca06197382bde0a3bc20215595d1c9ce20c6e341 , < d8cfbb8723bd3d3222f360227a1cc15227189ca6 (git)
    Affected: ca06197382bde0a3bc20215595d1c9ce20c6e341 , < 28c21f0ac5293a4bf19b3e0e32005d6dd31a6c17 (git)
    Affected: ca06197382bde0a3bc20215595d1c9ce20c6e341 , < 31beabd0f47f8c3ed9965ba861c9e5b252d4920a (git)
    Affected: ca06197382bde0a3bc20215595d1c9ce20c6e341 , < dc1d7afceb982e8f666e70a582e6b5aa806de063 (git)
    Affected: ca06197382bde0a3bc20215595d1c9ce20c6e341 , < d9ea94f5cd117d56e573696d0045ab3044185a15 (git)
    Affected: ca06197382bde0a3bc20215595d1c9ce20c6e341 , < fee873761bd978d077d8c55334b4966ac4cb7b59 (git)
    Create a notification for this product.
    Linux Linux Affected: 5.7
    Unaffected: 0 , < 5.7 (semver)
    Unaffected: 5.10.234 , ≤ 5.10.* (semver)
    Unaffected: 5.15.177 , ≤ 5.15.* (semver)
    Unaffected: 6.1.125 , ≤ 6.1.* (semver)
    Unaffected: 6.6.72 , ≤ 6.6.* (semver)
    Unaffected: 6.12.10 , ≤ 6.12.* (semver)
    Unaffected: 6.13 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:56:09.764Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:01:40.296Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "fs/exfat/dir.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "d8cfbb8723bd3d3222f360227a1cc15227189ca6",
                  "status": "affected",
                  "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                  "versionType": "git"
                },
                {
                  "lessThan": "28c21f0ac5293a4bf19b3e0e32005d6dd31a6c17",
                  "status": "affected",
                  "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                  "versionType": "git"
                },
                {
                  "lessThan": "31beabd0f47f8c3ed9965ba861c9e5b252d4920a",
                  "status": "affected",
                  "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                  "versionType": "git"
                },
                {
                  "lessThan": "dc1d7afceb982e8f666e70a582e6b5aa806de063",
                  "status": "affected",
                  "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                  "versionType": "git"
                },
                {
                  "lessThan": "d9ea94f5cd117d56e573696d0045ab3044185a15",
                  "status": "affected",
                  "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                  "versionType": "git"
                },
                {
                  "lessThan": "fee873761bd978d077d8c55334b4966ac4cb7b59",
                  "status": "affected",
                  "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "fs/exfat/dir.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.7"
                },
                {
                  "lessThan": "5.7",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.234",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.177",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.125",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.72",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.13",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.234",
                      "versionStartIncluding": "5.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.177",
                      "versionStartIncluding": "5.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.125",
                      "versionStartIncluding": "5.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.72",
                      "versionStartIncluding": "5.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.10",
                      "versionStartIncluding": "5.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13",
                      "versionStartIncluding": "5.7",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix the infinite loop in exfat_readdir()\n\nIf the file system is corrupted so that a cluster is linked to\nitself in the cluster chain, and there is an unused directory\nentry in the cluster, \u0027dentry\u0027 will not be incremented, causing\ncondition \u0027dentry \u003c max_dentries\u0027 unable to prevent an infinite\nloop.\n\nThis infinite loop causes s_lock not to be released, and other\ntasks will hang, such as exfat_sync_fs().\n\nThis commit stops traversing the cluster chain when there is unused\ndirectory entry in the cluster to avoid this infinite loop."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T21:01:04.019Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/d8cfbb8723bd3d3222f360227a1cc15227189ca6"
            },
            {
              "url": "https://git.kernel.org/stable/c/28c21f0ac5293a4bf19b3e0e32005d6dd31a6c17"
            },
            {
              "url": "https://git.kernel.org/stable/c/31beabd0f47f8c3ed9965ba861c9e5b252d4920a"
            },
            {
              "url": "https://git.kernel.org/stable/c/dc1d7afceb982e8f666e70a582e6b5aa806de063"
            },
            {
              "url": "https://git.kernel.org/stable/c/d9ea94f5cd117d56e573696d0045ab3044185a15"
            },
            {
              "url": "https://git.kernel.org/stable/c/fee873761bd978d077d8c55334b4966ac4cb7b59"
            }
          ],
          "title": "exfat: fix the infinite loop in exfat_readdir()",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-57940",
        "datePublished": "2025-01-21T12:18:09.150Z",
        "dateReserved": "2025-01-19T11:50:08.378Z",
        "dateUpdated": "2026-05-12T12:01:40.296Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-21653 (GCVE-0-2025-21653)

    Vulnerability from nvd – Published: 2025-01-19 10:18 – Updated: 2026-05-12 12:03
    VLAI
    Title
    net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute
    Summary
    In the Linux kernel, the following vulnerability has been resolved: net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute syzbot found that TCA_FLOW_RSHIFT attribute was not validated. Right shitfing a 32bit integer is undefined for large shift values. UBSAN: shift-out-of-bounds in net/sched/cls_flow.c:329:23 shift exponent 9445 is too large for 32-bit type 'u32' (aka 'unsigned int') CPU: 1 UID: 0 PID: 54 Comm: kworker/u8:3 Not tainted 6.13.0-rc3-syzkaller-00180-g4f619d518db9 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 Workqueue: ipv6_addrconf addrconf_dad_work Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120 ubsan_epilogue lib/ubsan.c:231 [inline] __ubsan_handle_shift_out_of_bounds+0x3c8/0x420 lib/ubsan.c:468 flow_classify+0x24d5/0x25b0 net/sched/cls_flow.c:329 tc_classify include/net/tc_wrapper.h:197 [inline] __tcf_classify net/sched/cls_api.c:1771 [inline] tcf_classify+0x420/0x1160 net/sched/cls_api.c:1867 sfb_classify net/sched/sch_sfb.c:260 [inline] sfb_enqueue+0x3ad/0x18b0 net/sched/sch_sfb.c:318 dev_qdisc_enqueue+0x4b/0x290 net/core/dev.c:3793 __dev_xmit_skb net/core/dev.c:3889 [inline] __dev_queue_xmit+0xf0e/0x3f50 net/core/dev.c:4400 dev_queue_xmit include/linux/netdevice.h:3168 [inline] neigh_hh_output include/net/neighbour.h:523 [inline] neigh_output include/net/neighbour.h:537 [inline] ip_finish_output2+0xd41/0x1390 net/ipv4/ip_output.c:236 iptunnel_xmit+0x55d/0x9b0 net/ipv4/ip_tunnel_core.c:82 udp_tunnel_xmit_skb+0x262/0x3b0 net/ipv4/udp_tunnel_core.c:173 geneve_xmit_skb drivers/net/geneve.c:916 [inline] geneve_xmit+0x21dc/0x2d00 drivers/net/geneve.c:1039 __netdev_start_xmit include/linux/netdevice.h:5002 [inline] netdev_start_xmit include/linux/netdevice.h:5011 [inline] xmit_one net/core/dev.c:3590 [inline] dev_hard_start_xmit+0x27a/0x7d0 net/core/dev.c:3606 __dev_queue_xmit+0x1b73/0x3f50 net/core/dev.c:4434
    Severity
    No CVSS data available.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: e5dfb815181fcb186d6080ac3a091eadff2d98fe , < 9858f4afeb2e59506e714176bd3e135539a3eeec (git)
    Affected: e5dfb815181fcb186d6080ac3a091eadff2d98fe , < 43658e4a5f2770ad94e93362885ff51c10cf3179 (git)
    Affected: e5dfb815181fcb186d6080ac3a091eadff2d98fe , < a313d6e6d5f3a631cae5a241c392c28868aa5c5e (git)
    Affected: e5dfb815181fcb186d6080ac3a091eadff2d98fe , < 2011749ca96460386844dfc7e0fde53ebee96f3c (git)
    Affected: e5dfb815181fcb186d6080ac3a091eadff2d98fe , < e54beb9aed2a90dddf4c5d68fcfc9a01f3e40a61 (git)
    Affected: e5dfb815181fcb186d6080ac3a091eadff2d98fe , < 6fde663f7321418996645ee602a473457640542f (git)
    Affected: e5dfb815181fcb186d6080ac3a091eadff2d98fe , < a039e54397c6a75b713b9ce7894a62e06956aa92 (git)
    Create a notification for this product.
    Linux Linux Affected: 2.6.25
    Unaffected: 0 , < 2.6.25 (semver)
    Unaffected: 5.4.290 , ≤ 5.4.* (semver)
    Unaffected: 5.10.234 , ≤ 5.10.* (semver)
    Unaffected: 5.15.177 , ≤ 5.15.* (semver)
    Unaffected: 6.1.125 , ≤ 6.1.* (semver)
    Unaffected: 6.6.72 , ≤ 6.6.* (semver)
    Unaffected: 6.12.10 , ≤ 6.12.* (semver)
    Unaffected: 6.13 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:58:33.343Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:03:05.797Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/sched/cls_flow.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "9858f4afeb2e59506e714176bd3e135539a3eeec",
                  "status": "affected",
                  "version": "e5dfb815181fcb186d6080ac3a091eadff2d98fe",
                  "versionType": "git"
                },
                {
                  "lessThan": "43658e4a5f2770ad94e93362885ff51c10cf3179",
                  "status": "affected",
                  "version": "e5dfb815181fcb186d6080ac3a091eadff2d98fe",
                  "versionType": "git"
                },
                {
                  "lessThan": "a313d6e6d5f3a631cae5a241c392c28868aa5c5e",
                  "status": "affected",
                  "version": "e5dfb815181fcb186d6080ac3a091eadff2d98fe",
                  "versionType": "git"
                },
                {
                  "lessThan": "2011749ca96460386844dfc7e0fde53ebee96f3c",
                  "status": "affected",
                  "version": "e5dfb815181fcb186d6080ac3a091eadff2d98fe",
                  "versionType": "git"
                },
                {
                  "lessThan": "e54beb9aed2a90dddf4c5d68fcfc9a01f3e40a61",
                  "status": "affected",
                  "version": "e5dfb815181fcb186d6080ac3a091eadff2d98fe",
                  "versionType": "git"
                },
                {
                  "lessThan": "6fde663f7321418996645ee602a473457640542f",
                  "status": "affected",
                  "version": "e5dfb815181fcb186d6080ac3a091eadff2d98fe",
                  "versionType": "git"
                },
                {
                  "lessThan": "a039e54397c6a75b713b9ce7894a62e06956aa92",
                  "status": "affected",
                  "version": "e5dfb815181fcb186d6080ac3a091eadff2d98fe",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/sched/cls_flow.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.6.25"
                },
                {
                  "lessThan": "2.6.25",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.290",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.234",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.177",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.125",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.72",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.13",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.290",
                      "versionStartIncluding": "2.6.25",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.234",
                      "versionStartIncluding": "2.6.25",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.177",
                      "versionStartIncluding": "2.6.25",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.125",
                      "versionStartIncluding": "2.6.25",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.72",
                      "versionStartIncluding": "2.6.25",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.10",
                      "versionStartIncluding": "2.6.25",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13",
                      "versionStartIncluding": "2.6.25",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute\n\nsyzbot found that TCA_FLOW_RSHIFT attribute was not validated.\nRight shitfing a 32bit integer is undefined for large shift values.\n\nUBSAN: shift-out-of-bounds in net/sched/cls_flow.c:329:23\nshift exponent 9445 is too large for 32-bit type \u0027u32\u0027 (aka \u0027unsigned int\u0027)\nCPU: 1 UID: 0 PID: 54 Comm: kworker/u8:3 Not tainted 6.13.0-rc3-syzkaller-00180-g4f619d518db9 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nWorkqueue: ipv6_addrconf addrconf_dad_work\nCall Trace:\n \u003cTASK\u003e\n  __dump_stack lib/dump_stack.c:94 [inline]\n  dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n  ubsan_epilogue lib/ubsan.c:231 [inline]\n  __ubsan_handle_shift_out_of_bounds+0x3c8/0x420 lib/ubsan.c:468\n  flow_classify+0x24d5/0x25b0 net/sched/cls_flow.c:329\n  tc_classify include/net/tc_wrapper.h:197 [inline]\n  __tcf_classify net/sched/cls_api.c:1771 [inline]\n  tcf_classify+0x420/0x1160 net/sched/cls_api.c:1867\n  sfb_classify net/sched/sch_sfb.c:260 [inline]\n  sfb_enqueue+0x3ad/0x18b0 net/sched/sch_sfb.c:318\n  dev_qdisc_enqueue+0x4b/0x290 net/core/dev.c:3793\n  __dev_xmit_skb net/core/dev.c:3889 [inline]\n  __dev_queue_xmit+0xf0e/0x3f50 net/core/dev.c:4400\n  dev_queue_xmit include/linux/netdevice.h:3168 [inline]\n  neigh_hh_output include/net/neighbour.h:523 [inline]\n  neigh_output include/net/neighbour.h:537 [inline]\n  ip_finish_output2+0xd41/0x1390 net/ipv4/ip_output.c:236\n  iptunnel_xmit+0x55d/0x9b0 net/ipv4/ip_tunnel_core.c:82\n  udp_tunnel_xmit_skb+0x262/0x3b0 net/ipv4/udp_tunnel_core.c:173\n  geneve_xmit_skb drivers/net/geneve.c:916 [inline]\n  geneve_xmit+0x21dc/0x2d00 drivers/net/geneve.c:1039\n  __netdev_start_xmit include/linux/netdevice.h:5002 [inline]\n  netdev_start_xmit include/linux/netdevice.h:5011 [inline]\n  xmit_one net/core/dev.c:3590 [inline]\n  dev_hard_start_xmit+0x27a/0x7d0 net/core/dev.c:3606\n  __dev_queue_xmit+0x1b73/0x3f50 net/core/dev.c:4434"
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T21:03:50.397Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/9858f4afeb2e59506e714176bd3e135539a3eeec"
            },
            {
              "url": "https://git.kernel.org/stable/c/43658e4a5f2770ad94e93362885ff51c10cf3179"
            },
            {
              "url": "https://git.kernel.org/stable/c/a313d6e6d5f3a631cae5a241c392c28868aa5c5e"
            },
            {
              "url": "https://git.kernel.org/stable/c/2011749ca96460386844dfc7e0fde53ebee96f3c"
            },
            {
              "url": "https://git.kernel.org/stable/c/e54beb9aed2a90dddf4c5d68fcfc9a01f3e40a61"
            },
            {
              "url": "https://git.kernel.org/stable/c/6fde663f7321418996645ee602a473457640542f"
            },
            {
              "url": "https://git.kernel.org/stable/c/a039e54397c6a75b713b9ce7894a62e06956aa92"
            }
          ],
          "title": "net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2025-21653",
        "datePublished": "2025-01-19T10:18:10.354Z",
        "dateReserved": "2024-12-29T08:45:45.729Z",
        "dateUpdated": "2026-05-12T12:03:05.797Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-21647 (GCVE-0-2025-21647)

    Vulnerability from nvd – Published: 2025-01-19 10:18 – Updated: 2026-08-05 11:53
    VLAI
    Title
    sched: sch_cake: add bounds checks to host bulk flow fairness counts
    Summary
    In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: add bounds checks to host bulk flow fairness counts Even though we fixed a logic error in the commit cited below, syzbot still managed to trigger an underflow of the per-host bulk flow counters, leading to an out of bounds memory access. To avoid any such logic errors causing out of bounds memory accesses, this commit factors out all accesses to the per-host bulk flow counters to a series of helpers that perform bounds-checking before any increments and decrements. This also has the benefit of improving readability by moving the conditional checks for the flow mode into these helpers, instead of having them spread out throughout the code (which was the cause of the original logic error). As part of this change, the flow quantum calculation is consolidated into a helper function, which means that the dithering applied to the ost load scaling is now applied both in the DRR rotation and when a sparse flow's quantum is first initiated. The only user-visible effect of this is that the maximum packet size that can be sent while a flow stays sparse will now vary with +/- one byte in some cases. This should not make a noticeable difference in practice, and thus it's not worth complicating the code to preserve the old behaviour.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 4a4eeefa514db570be025ab46d779af180e2c9bb , < 44fe1efb4961c1a5ccab16bb579dfc6b308ad58b (git)
    Affected: 7725152b54d295b7da5e34c2f419539b30d017bd , < b1a1743aaa4906c41c426eda97e2e2586f79246d (git)
    Affected: cde71a5677971f4f1b69b25e854891dbe78066a4 , < bb0245fa72b783cb23a9949c5048781341e91423 (git)
    Affected: 549e407569e08459d16122341d332cb508024094 , < a777e06dfc72bed73c05dcb437d7c27ad5f90f3f (git)
    Affected: d4a9039a7b3d8005b90c7b1a55a306444f0e5447 , < 27202e2e8721c3b23831563c36ed5ac7818641ba (git)
    Affected: 546ea84d07e3e324644025e2aae2d12ea4c5896e , < 91bb18950b88f955838ec0c1d97f74d135756dc7 (git)
    Affected: 546ea84d07e3e324644025e2aae2d12ea4c5896e , < 737d4d91d35b5f7fa5bb442651472277318b0bfd (git)
    Affected: d7c01c0714c04431b5e18cf17a9ea68a553d1c3c (git)
    Affected: 5.4.284 , < 5.4.291 (semver)
    Affected: 5.10.226 , < 5.10.235 (semver)
    Affected: 5.15.167 , < 5.15.179 (semver)
    Affected: 6.1.110 , < 6.1.125 (semver)
    Affected: 6.6.51 , < 6.6.72 (semver)
    Affected: 6.10.10 , < 6.11 (semver)
    Create a notification for this product.
    Linux Linux Affected: 6.11
    Unaffected: 0 , < 6.11 (semver)
    Unaffected: 5.4.291 , ≤ 5.4.* (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.125 , ≤ 6.1.* (semver)
    Unaffected: 6.6.72 , ≤ 6.6.* (semver)
    Unaffected: 6.12.10 , ≤ 6.12.* (semver)
    Unaffected: 6.13 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:58:27.786Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:03:03.268Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/sched/sch_cake.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "44fe1efb4961c1a5ccab16bb579dfc6b308ad58b",
                  "status": "affected",
                  "version": "4a4eeefa514db570be025ab46d779af180e2c9bb",
                  "versionType": "git"
                },
                {
                  "lessThan": "b1a1743aaa4906c41c426eda97e2e2586f79246d",
                  "status": "affected",
                  "version": "7725152b54d295b7da5e34c2f419539b30d017bd",
                  "versionType": "git"
                },
                {
                  "lessThan": "bb0245fa72b783cb23a9949c5048781341e91423",
                  "status": "affected",
                  "version": "cde71a5677971f4f1b69b25e854891dbe78066a4",
                  "versionType": "git"
                },
                {
                  "lessThan": "a777e06dfc72bed73c05dcb437d7c27ad5f90f3f",
                  "status": "affected",
                  "version": "549e407569e08459d16122341d332cb508024094",
                  "versionType": "git"
                },
                {
                  "lessThan": "27202e2e8721c3b23831563c36ed5ac7818641ba",
                  "status": "affected",
                  "version": "d4a9039a7b3d8005b90c7b1a55a306444f0e5447",
                  "versionType": "git"
                },
                {
                  "lessThan": "91bb18950b88f955838ec0c1d97f74d135756dc7",
                  "status": "affected",
                  "version": "546ea84d07e3e324644025e2aae2d12ea4c5896e",
                  "versionType": "git"
                },
                {
                  "lessThan": "737d4d91d35b5f7fa5bb442651472277318b0bfd",
                  "status": "affected",
                  "version": "546ea84d07e3e324644025e2aae2d12ea4c5896e",
                  "versionType": "git"
                },
                {
                  "status": "affected",
                  "version": "d7c01c0714c04431b5e18cf17a9ea68a553d1c3c",
                  "versionType": "git"
                },
                {
                  "lessThan": "5.4.291",
                  "status": "affected",
                  "version": "5.4.284",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.10.235",
                  "status": "affected",
                  "version": "5.10.226",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.15.179",
                  "status": "affected",
                  "version": "5.15.167",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.1.125",
                  "status": "affected",
                  "version": "6.1.110",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.6.72",
                  "status": "affected",
                  "version": "6.6.51",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.11",
                  "status": "affected",
                  "version": "6.10.10",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/sched/sch_cake.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.11"
                },
                {
                  "lessThan": "6.11",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.291",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.125",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.72",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.13",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.291",
                      "versionStartIncluding": "5.4.284",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "5.10.226",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "5.15.167",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.125",
                      "versionStartIncluding": "6.1.110",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.72",
                      "versionStartIncluding": "6.6.51",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.10",
                      "versionStartIncluding": "6.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13",
                      "versionStartIncluding": "6.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionStartIncluding": "6.10.10",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched: sch_cake: add bounds checks to host bulk flow fairness counts\n\nEven though we fixed a logic error in the commit cited below, syzbot\nstill managed to trigger an underflow of the per-host bulk flow\ncounters, leading to an out of bounds memory access.\n\nTo avoid any such logic errors causing out of bounds memory accesses,\nthis commit factors out all accesses to the per-host bulk flow counters\nto a series of helpers that perform bounds-checking before any\nincrements and decrements. This also has the benefit of improving\nreadability by moving the conditional checks for the flow mode into\nthese helpers, instead of having them spread out throughout the\ncode (which was the cause of the original logic error).\n\nAs part of this change, the flow quantum calculation is consolidated\ninto a helper function, which means that the dithering applied to the\nost load scaling is now applied both in the DRR rotation and when a\nsparse flow\u0027s quantum is first initiated. The only user-visible effect\nof this is that the maximum packet size that can be sent while a flow\nstays sparse will now vary with +/- one byte in some cases. This should\nnot make a noticeable difference in practice, and thus it\u0027s not worth\ncomplicating the code to preserve the old behaviour."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - Reaching the bug requires attaching the cake qdisc via rtnetlink (`tc qdisc add ... cake`) and then driving packets through it, which is a local netlink/syscall operation. Although cake also processes remotely-originated traffic on routers, the reliable and primary attack path is local, consistent with tc/qdisc classification.\nAC:L - The vulnerable host-fairness accounting is active in cake\u0027s default `triple-isolate` flow mode, and the attacker fully controls the packet 5-tuples used for the set-associative hash, so filling an 8-way set and forcing the mis-targeted decrement is deterministic and repeatable.\nPR:L - Qdisc installation is gated by `netlink_net_capable(skb, CAP_NET_ADMIN)`, which is evaluated against the netns user namespace, so any unprivileged user can obtain it with `unshare -Urn` and then attach cake to a loopback/veth device.\nUI:N - The attacker performs the qdisc setup and generates the triggering traffic entirely on their own; no action by any other user or administrator is needed.\nS:U - The out-of-bounds read and the counter corruption are confined to kernel memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The u16 underflow makes `quantum_div[host_load]` read up to ~128 KB beyond a 1025-entry static array, and the value is folded into `flow-\u003edeficit`, which is exported via `TCA_CAKE_STATS_DEFICIT` \u2014 repeated samples defeat the random dithering and recover out-of-bounds kernel data, with the index steerable by additional spurious decrements.\nI:L - The bug persistently corrupts the per-host bulk-flow counters and injects out-of-bounds data into the scheduler\u0027s deficit state, modifying kernel data the attacker should not be able to touch, but there is no out-of-bounds write and no control over the written values.\nA:H - The wild index trips `WARN_ON(host_load \u003e CAKE_QUEUES)` (a panic under `panic_on_warn`) and reads far past the module\u0027s `.bss` into potentially unmapped vmalloc space, causing an oops; the qdisc state stays corrupted so the condition recurs on every dequeue."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:53:21.504Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/44fe1efb4961c1a5ccab16bb579dfc6b308ad58b"
            },
            {
              "url": "https://git.kernel.org/stable/c/b1a1743aaa4906c41c426eda97e2e2586f79246d"
            },
            {
              "url": "https://git.kernel.org/stable/c/bb0245fa72b783cb23a9949c5048781341e91423"
            },
            {
              "url": "https://git.kernel.org/stable/c/a777e06dfc72bed73c05dcb437d7c27ad5f90f3f"
            },
            {
              "url": "https://git.kernel.org/stable/c/27202e2e8721c3b23831563c36ed5ac7818641ba"
            },
            {
              "url": "https://git.kernel.org/stable/c/91bb18950b88f955838ec0c1d97f74d135756dc7"
            },
            {
              "url": "https://git.kernel.org/stable/c/737d4d91d35b5f7fa5bb442651472277318b0bfd"
            }
          ],
          "title": "sched: sch_cake: add bounds checks to host bulk flow fairness counts",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2025-21647",
        "datePublished": "2025-01-19T10:18:04.415Z",
        "dateReserved": "2024-12-29T08:45:45.728Z",
        "dateUpdated": "2026-08-05T11:53:21.504Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-53124 (GCVE-0-2024-53124)

    Vulnerability from nvd – Published: 2024-12-02 13:44 – Updated: 2026-09-08 08:39
    VLAI
    Title
    net: fix data-races around sk->sk_forward_alloc
    Summary
    In the Linux kernel, the following vulnerability has been resolved: net: fix data-races around sk->sk_forward_alloc Syzkaller reported this warning: ------------[ cut here ]------------ WARNING: CPU: 0 PID: 16 at net/ipv4/af_inet.c:156 inet_sock_destruct+0x1c5/0x1e0 Modules linked in: CPU: 0 UID: 0 PID: 16 Comm: ksoftirqd/0 Not tainted 6.12.0-rc5 #26 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 RIP: 0010:inet_sock_destruct+0x1c5/0x1e0 Code: 24 12 4c 89 e2 5b 48 c7 c7 98 ec bb 82 41 5c e9 d1 18 17 ff 4c 89 e6 5b 48 c7 c7 d0 ec bb 82 41 5c e9 bf 18 17 ff 0f 0b eb 83 <0f> 0b eb 97 0f 0b eb 87 0f 0b e9 68 ff ff ff 66 66 2e 0f 1f 84 00 RSP: 0018:ffffc9000008bd90 EFLAGS: 00010206 RAX: 0000000000000300 RBX: ffff88810b172a90 RCX: 0000000000000007 RDX: 0000000000000002 RSI: 0000000000000300 RDI: ffff88810b172a00 RBP: ffff88810b172a00 R08: ffff888104273c00 R09: 0000000000100007 R10: 0000000000020000 R11: 0000000000000006 R12: ffff88810b172a00 R13: 0000000000000004 R14: 0000000000000000 R15: ffff888237c31f78 FS: 0000000000000000(0000) GS:ffff888237c00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007ffc63fecac8 CR3: 000000000342e000 CR4: 00000000000006f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> ? __warn+0x88/0x130 ? inet_sock_destruct+0x1c5/0x1e0 ? report_bug+0x18e/0x1a0 ? handle_bug+0x53/0x90 ? exc_invalid_op+0x18/0x70 ? asm_exc_invalid_op+0x1a/0x20 ? inet_sock_destruct+0x1c5/0x1e0 __sk_destruct+0x2a/0x200 rcu_do_batch+0x1aa/0x530 ? rcu_do_batch+0x13b/0x530 rcu_core+0x159/0x2f0 handle_softirqs+0xd3/0x2b0 ? __pfx_smpboot_thread_fn+0x10/0x10 run_ksoftirqd+0x25/0x30 smpboot_thread_fn+0xdd/0x1d0 kthread+0xd3/0x100 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x34/0x50 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 </TASK> ---[ end trace 0000000000000000 ]--- Its possible that two threads call tcp_v6_do_rcv()/sk_forward_alloc_add() concurrently when sk->sk_state == TCP_LISTEN with sk->sk_lock unlocked, which triggers a data-race around sk->sk_forward_alloc: tcp_v6_rcv tcp_v6_do_rcv skb_clone_and_charge_r sk_rmem_schedule __sk_mem_schedule sk_forward_alloc_add() skb_set_owner_r sk_mem_charge sk_forward_alloc_add() __kfree_skb skb_release_all skb_release_head_state sock_rfree sk_mem_uncharge sk_forward_alloc_add() sk_mem_reclaim // set local var reclaimable __sk_mem_reclaim sk_forward_alloc_add() In this syzkaller testcase, two threads call tcp_v6_do_rcv() with skb->truesize=768, the sk_forward_alloc changes like this: (cpu 1) | (cpu 2) | sk_forward_alloc ... | ... | 0 __sk_mem_schedule() | | +4096 = 4096 | __sk_mem_schedule() | +4096 = 8192 sk_mem_charge() | | -768 = 7424 | sk_mem_charge() | -768 = 6656 ... | ... | sk_mem_uncharge() | | +768 = 7424 reclaimable=7424 | | | sk_mem_uncharge() | +768 = 8192 | reclaimable=8192 | __sk_mem_reclaim() | | -4096 = 4096 | __sk_mem_reclaim() | -8192 = -4096 != 0 The skb_clone_and_charge_r() should not be called in tcp_v6_do_rcv() when sk->sk_state is TCP_LISTEN, it happens later in tcp_v6_syn_recv_sock(). Fix the same issue in dccp_v6_do_rcv().
    Impacted products
    Vendor Product Version
    Linux Linux Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < 695fb0b9aecfd5dd5b2946ba8897ac2c1eef654d (git)
    Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < fe2c0bd6d1e29ccefdc978b9a290571c93c27473 (git)
    Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < c3d052cae566ec2285f5999958a5deb415a0f59e (git)
    Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < be7c61ea5f816168c38955eb4e898adc8b4b32fd (git)
    Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < 3f51f8c9d28954cf380100883a02eed35a8277e9 (git)
    Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < d285eb9d0641c8344f2836081b4ccb7b3c5cc1b6 (git)
    Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < 073d89808c065ac4c672c0a613a71b27a80691cb (git)
    Create a notification for this product.
    Linux Linux Affected: 4.4
    Unaffected: 0 , < 4.4 (semver)
    Unaffected: 5.4.290 , ≤ 5.4.* (semver)
    Unaffected: 5.10.234 , ≤ 5.10.* (semver)
    Unaffected: 5.15.177 , ≤ 5.15.* (semver)
    Unaffected: 6.1.127 , ≤ 6.1.* (semver)
    Unaffected: 6.6.74 , ≤ 6.6.* (semver)
    Unaffected: 6.11.10 , ≤ 6.11.* (semver)
    Unaffected: 6.12 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.6 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP Affected: V3.1.6 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.6 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.0 , < V3.1.5 (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP Affected: V3.1.0 , < V3.1.5 (custom)
    Create a notification for this product.
    Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.0 , < V3.1.5 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:46:04.223Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.6",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.6",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.6",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.6",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.6",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T08:39:37.903Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-398330.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/dccp/ipv6.c",
                "net/ipv6/tcp_ipv6.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "695fb0b9aecfd5dd5b2946ba8897ac2c1eef654d",
                  "status": "affected",
                  "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                  "versionType": "git"
                },
                {
                  "lessThan": "fe2c0bd6d1e29ccefdc978b9a290571c93c27473",
                  "status": "affected",
                  "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                  "versionType": "git"
                },
                {
                  "lessThan": "c3d052cae566ec2285f5999958a5deb415a0f59e",
                  "status": "affected",
                  "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                  "versionType": "git"
                },
                {
                  "lessThan": "be7c61ea5f816168c38955eb4e898adc8b4b32fd",
                  "status": "affected",
                  "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                  "versionType": "git"
                },
                {
                  "lessThan": "3f51f8c9d28954cf380100883a02eed35a8277e9",
                  "status": "affected",
                  "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                  "versionType": "git"
                },
                {
                  "lessThan": "d285eb9d0641c8344f2836081b4ccb7b3c5cc1b6",
                  "status": "affected",
                  "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                  "versionType": "git"
                },
                {
                  "lessThan": "073d89808c065ac4c672c0a613a71b27a80691cb",
                  "status": "affected",
                  "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/dccp/ipv6.c",
                "net/ipv6/tcp_ipv6.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.4"
                },
                {
                  "lessThan": "4.4",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.290",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.234",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.177",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.127",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.74",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.11.*",
                  "status": "unaffected",
                  "version": "6.11.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.12",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.290",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.234",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.177",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.127",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.74",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.11.10",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix data-races around sk-\u003esk_forward_alloc\n\nSyzkaller reported this warning:\n ------------[ cut here ]------------\n WARNING: CPU: 0 PID: 16 at net/ipv4/af_inet.c:156 inet_sock_destruct+0x1c5/0x1e0\n Modules linked in:\n CPU: 0 UID: 0 PID: 16 Comm: ksoftirqd/0 Not tainted 6.12.0-rc5 #26\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n RIP: 0010:inet_sock_destruct+0x1c5/0x1e0\n Code: 24 12 4c 89 e2 5b 48 c7 c7 98 ec bb 82 41 5c e9 d1 18 17 ff 4c 89 e6 5b 48 c7 c7 d0 ec bb 82 41 5c e9 bf 18 17 ff 0f 0b eb 83 \u003c0f\u003e 0b eb 97 0f 0b eb 87 0f 0b e9 68 ff ff ff 66 66 2e 0f 1f 84 00\n RSP: 0018:ffffc9000008bd90 EFLAGS: 00010206\n RAX: 0000000000000300 RBX: ffff88810b172a90 RCX: 0000000000000007\n RDX: 0000000000000002 RSI: 0000000000000300 RDI: ffff88810b172a00\n RBP: ffff88810b172a00 R08: ffff888104273c00 R09: 0000000000100007\n R10: 0000000000020000 R11: 0000000000000006 R12: ffff88810b172a00\n R13: 0000000000000004 R14: 0000000000000000 R15: ffff888237c31f78\n FS:  0000000000000000(0000) GS:ffff888237c00000(0000) knlGS:0000000000000000\n CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007ffc63fecac8 CR3: 000000000342e000 CR4: 00000000000006f0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n  \u003cTASK\u003e\n  ? __warn+0x88/0x130\n  ? inet_sock_destruct+0x1c5/0x1e0\n  ? report_bug+0x18e/0x1a0\n  ? handle_bug+0x53/0x90\n  ? exc_invalid_op+0x18/0x70\n  ? asm_exc_invalid_op+0x1a/0x20\n  ? inet_sock_destruct+0x1c5/0x1e0\n  __sk_destruct+0x2a/0x200\n  rcu_do_batch+0x1aa/0x530\n  ? rcu_do_batch+0x13b/0x530\n  rcu_core+0x159/0x2f0\n  handle_softirqs+0xd3/0x2b0\n  ? __pfx_smpboot_thread_fn+0x10/0x10\n  run_ksoftirqd+0x25/0x30\n  smpboot_thread_fn+0xdd/0x1d0\n  kthread+0xd3/0x100\n  ? __pfx_kthread+0x10/0x10\n  ret_from_fork+0x34/0x50\n  ? __pfx_kthread+0x10/0x10\n  ret_from_fork_asm+0x1a/0x30\n  \u003c/TASK\u003e\n ---[ end trace 0000000000000000 ]---\n\nIts possible that two threads call tcp_v6_do_rcv()/sk_forward_alloc_add()\nconcurrently when sk-\u003esk_state == TCP_LISTEN with sk-\u003esk_lock unlocked,\nwhich triggers a data-race around sk-\u003esk_forward_alloc:\ntcp_v6_rcv\n    tcp_v6_do_rcv\n        skb_clone_and_charge_r\n            sk_rmem_schedule\n                __sk_mem_schedule\n                    sk_forward_alloc_add()\n            skb_set_owner_r\n                sk_mem_charge\n                    sk_forward_alloc_add()\n        __kfree_skb\n            skb_release_all\n                skb_release_head_state\n                    sock_rfree\n                        sk_mem_uncharge\n                            sk_forward_alloc_add()\n                            sk_mem_reclaim\n                                // set local var reclaimable\n                                __sk_mem_reclaim\n                                    sk_forward_alloc_add()\n\nIn this syzkaller testcase, two threads call\ntcp_v6_do_rcv() with skb-\u003etruesize=768, the sk_forward_alloc changes like\nthis:\n (cpu 1)             | (cpu 2)             | sk_forward_alloc\n ...                 | ...                 | 0\n __sk_mem_schedule() |                     | +4096 = 4096\n                     | __sk_mem_schedule() | +4096 = 8192\n sk_mem_charge()     |                     | -768  = 7424\n                     | sk_mem_charge()     | -768  = 6656\n ...                 |    ...              |\n sk_mem_uncharge()   |                     | +768  = 7424\n reclaimable=7424    |                     |\n                     | sk_mem_uncharge()   | +768  = 8192\n                     | reclaimable=8192    |\n __sk_mem_reclaim()  |                     | -4096 = 4096\n                     | __sk_mem_reclaim()  | -8192 = -4096 != 0\n\nThe skb_clone_and_charge_r() should not be called in tcp_v6_do_rcv() when\nsk-\u003esk_state is TCP_LISTEN, it happens later in tcp_v6_syn_recv_sock().\nFix the same issue in dccp_v6_do_rcv()."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:N - The vulnerable code is in the IPv6 TCP receive path (`tcp_v6_rcv()` \u2192 `tcp_v6_do_rcv()`), executed directly on inbound SYN packets from any remote peer; a remote attacker reaches it by sending TCP/IPv6 segments to a listening socket. The same defect exists in the DCCP IPv6 receive path.\nAC:L - The attacker controls both sides of the race by sending a burst of concurrent SYNs from different source ports/addresses, which RSS/RPS distributes across CPUs that all enter `tcp_v6_do_rcv()` on the same listener with no socket lock held. No memory layout, timing window outside attacker influence, or victim state is required, and syzkaller reproduces it routinely.\nPR:N - The racing code runs while processing a SYN on a listening socket, entirely before connection establishment or any authentication, so no credentials of any kind are needed. Setting the `IPV6_RECV*` option that arms the path is done by the victim server (or by an unprivileged local user on their own listener), not by the attacker.\nUI:N - Triggering requires only that packets be sent to an already-listening socket; no action by any local user or administrator is needed.\nS:U - The corrupted state (`sk-\u003esk_forward_alloc`, `tcp_memory_allocated`, memcg skmem counters) and the resulting warning/panic are all within the kernel\u0027s own security authority, with no crossing into a hypervisor, IOMMU, or other separate authority.\nC:N - The defect is a non-atomic read-modify-write on integer accounting counters; it produces no out-of-bounds read, no use-after-free, and no path by which memory contents or kernel pointers are disclosed to the attacker.\nI:N - No attacker-controlled data is written and no memory corruption primitive is created \u2014 only the socket\u0027s own memory-accounting counters become inconsistent, which is not a modification of protected data or control flow.\nA:H - The imbalance trips `WARN_ON_ONCE(sk_forward_alloc_get(sk))` in `inet_sock_destruct()` from softirq context, which is an immediate kernel panic on `panic_on_warn` systems, and the over-reclaim corrupts the global `tcp_memory_allocated` counter and memcg skmem accounting, breaking system-wide TCP memory limits (unbounded growth toward OOM, or permanent memory pressure across all TCP sockets). It is repeatable at will by an unauthenticated remote attacker."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:43:54.069Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/695fb0b9aecfd5dd5b2946ba8897ac2c1eef654d"
            },
            {
              "url": "https://git.kernel.org/stable/c/fe2c0bd6d1e29ccefdc978b9a290571c93c27473"
            },
            {
              "url": "https://git.kernel.org/stable/c/c3d052cae566ec2285f5999958a5deb415a0f59e"
            },
            {
              "url": "https://git.kernel.org/stable/c/be7c61ea5f816168c38955eb4e898adc8b4b32fd"
            },
            {
              "url": "https://git.kernel.org/stable/c/3f51f8c9d28954cf380100883a02eed35a8277e9"
            },
            {
              "url": "https://git.kernel.org/stable/c/d285eb9d0641c8344f2836081b4ccb7b3c5cc1b6"
            },
            {
              "url": "https://git.kernel.org/stable/c/073d89808c065ac4c672c0a613a71b27a80691cb"
            }
          ],
          "title": "net: fix data-races around sk-\u003esk_forward_alloc",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-53124",
        "datePublished": "2024-12-02T13:44:54.257Z",
        "dateReserved": "2024-11-19T17:17:24.995Z",
        "dateUpdated": "2026-09-08T08:39:37.903Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-26982 (GCVE-0-2024-26982)

    Vulnerability from nvd – Published: 2024-05-01 05:27 – Updated: 2026-05-12 11:50
    VLAI
    Title
    Squashfs: check the inode number is not the invalid value of zero
    Summary
    In the Linux kernel, the following vulnerability has been resolved: Squashfs: check the inode number is not the invalid value of zero Syskiller has produced an out of bounds access in fill_meta_index(). That out of bounds access is ultimately caused because the inode has an inode number with the invalid value of zero, which was not checked. The reason this causes the out of bounds access is due to following sequence of events: 1. Fill_meta_index() is called to allocate (via empty_meta_index()) and fill a metadata index. It however suffers a data read error and aborts, invalidating the newly returned empty metadata index. It does this by setting the inode number of the index to zero, which means unused (zero is not a valid inode number). 2. When fill_meta_index() is subsequently called again on another read operation, locate_meta_index() returns the previous index because it matches the inode number of 0. Because this index has been returned it is expected to have been filled, and because it hasn't been, an out of bounds access is performed. This patch adds a sanity check which checks that the inode number is not zero when the inode is created and returns -EINVAL if it is. [phillip@squashfs.org.uk: whitespace fix]
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 15:45 UTC
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 6545b246a2c815a8fcd07d58240effb6ec3481b1 , < 32c114a58236fe67141634774559f21f1dc96fd7 (git)
    Affected: 6545b246a2c815a8fcd07d58240effb6ec3481b1 , < 4a1b6f89825e267e156ccaeba3d235edcac77f94 (git)
    Affected: 6545b246a2c815a8fcd07d58240effb6ec3481b1 , < cf46f88b92cfc0e32bd8a21ba1273cff13b8745f (git)
    Affected: 6545b246a2c815a8fcd07d58240effb6ec3481b1 , < 5b99dea79650b50909c50aba24fbae00f203f013 (git)
    Affected: 6545b246a2c815a8fcd07d58240effb6ec3481b1 , < be383effaee3d89034f0828038f95065b518772e (git)
    Affected: 6545b246a2c815a8fcd07d58240effb6ec3481b1 , < 7def00ebc9f2d6a581ddf46ce4541f84a10680e5 (git)
    Affected: 6545b246a2c815a8fcd07d58240effb6ec3481b1 , < 9253c54e01b6505d348afbc02abaa4d9f8a01395 (git)
    Create a notification for this product.
    Linux Linux Affected: 2.6.29
    Unaffected: 0 , < 2.6.29 (semver)
    Unaffected: 5.4.291 , ≤ 5.4.* (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.130 , ≤ 6.1.* (semver)
    Unaffected: 6.6.30 , ≤ 6.6.* (semver)
    Unaffected: 6.8.8 , ≤ 6.8.* (semver)
    Unaffected: 6.9 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-04T17:15:00.359Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/be383effaee3d89034f0828038f95065b518772e"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/7def00ebc9f2d6a581ddf46ce4541f84a10680e5"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/9253c54e01b6505d348afbc02abaa4d9f8a01395"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              },
              {
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DAMSOZXJEPUOXW33WZYWCVAY7Z5S7OOY/"
              },
              {
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EZ6PJW7VOZ224TD7N4JZNU6KV32ZJ53/"
              },
              {
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCBZZEC7L7KTWWAS2NLJK6SO3IZIL4WW/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-26982",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T15:45:06.926436Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-11T17:33:42.999Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T11:50:59.992Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "fs/squashfs/inode.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "32c114a58236fe67141634774559f21f1dc96fd7",
                  "status": "affected",
                  "version": "6545b246a2c815a8fcd07d58240effb6ec3481b1",
                  "versionType": "git"
                },
                {
                  "lessThan": "4a1b6f89825e267e156ccaeba3d235edcac77f94",
                  "status": "affected",
                  "version": "6545b246a2c815a8fcd07d58240effb6ec3481b1",
                  "versionType": "git"
                },
                {
                  "lessThan": "cf46f88b92cfc0e32bd8a21ba1273cff13b8745f",
                  "status": "affected",
                  "version": "6545b246a2c815a8fcd07d58240effb6ec3481b1",
                  "versionType": "git"
                },
                {
                  "lessThan": "5b99dea79650b50909c50aba24fbae00f203f013",
                  "status": "affected",
                  "version": "6545b246a2c815a8fcd07d58240effb6ec3481b1",
                  "versionType": "git"
                },
                {
                  "lessThan": "be383effaee3d89034f0828038f95065b518772e",
                  "status": "affected",
                  "version": "6545b246a2c815a8fcd07d58240effb6ec3481b1",
                  "versionType": "git"
                },
                {
                  "lessThan": "7def00ebc9f2d6a581ddf46ce4541f84a10680e5",
                  "status": "affected",
                  "version": "6545b246a2c815a8fcd07d58240effb6ec3481b1",
                  "versionType": "git"
                },
                {
                  "lessThan": "9253c54e01b6505d348afbc02abaa4d9f8a01395",
                  "status": "affected",
                  "version": "6545b246a2c815a8fcd07d58240effb6ec3481b1",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "fs/squashfs/inode.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.6.29"
                },
                {
                  "lessThan": "2.6.29",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.291",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.130",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.30",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.8.*",
                  "status": "unaffected",
                  "version": "6.8.8",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.9",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.291",
                      "versionStartIncluding": "2.6.29",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "2.6.29",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "2.6.29",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.130",
                      "versionStartIncluding": "2.6.29",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.30",
                      "versionStartIncluding": "2.6.29",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.8.8",
                      "versionStartIncluding": "2.6.29",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9",
                      "versionStartIncluding": "2.6.29",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nSquashfs: check the inode number is not the invalid value of zero\n\nSyskiller has produced an out of bounds access in fill_meta_index().\n\nThat out of bounds access is ultimately caused because the inode\nhas an inode number with the invalid value of zero, which was not checked.\n\nThe reason this causes the out of bounds access is due to following\nsequence of events:\n\n1. Fill_meta_index() is called to allocate (via empty_meta_index())\n   and fill a metadata index.  It however suffers a data read error\n   and aborts, invalidating the newly returned empty metadata index.\n   It does this by setting the inode number of the index to zero,\n   which means unused (zero is not a valid inode number).\n\n2. When fill_meta_index() is subsequently called again on another\n   read operation, locate_meta_index() returns the previous index\n   because it matches the inode number of 0.  Because this index\n   has been returned it is expected to have been filled, and because\n   it hasn\u0027t been, an out of bounds access is performed.\n\nThis patch adds a sanity check which checks that the inode number\nis not zero when the inode is created and returns -EINVAL if it is.\n\n[phillip@squashfs.org.uk: whitespace fix]"
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T20:08:07.235Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/32c114a58236fe67141634774559f21f1dc96fd7"
            },
            {
              "url": "https://git.kernel.org/stable/c/4a1b6f89825e267e156ccaeba3d235edcac77f94"
            },
            {
              "url": "https://git.kernel.org/stable/c/cf46f88b92cfc0e32bd8a21ba1273cff13b8745f"
            },
            {
              "url": "https://git.kernel.org/stable/c/5b99dea79650b50909c50aba24fbae00f203f013"
            },
            {
              "url": "https://git.kernel.org/stable/c/be383effaee3d89034f0828038f95065b518772e"
            },
            {
              "url": "https://git.kernel.org/stable/c/7def00ebc9f2d6a581ddf46ce4541f84a10680e5"
            },
            {
              "url": "https://git.kernel.org/stable/c/9253c54e01b6505d348afbc02abaa4d9f8a01395"
            }
          ],
          "title": "Squashfs: check the inode number is not the invalid value of zero",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-26982",
        "datePublished": "2024-05-01T05:27:11.032Z",
        "dateReserved": "2024-02-19T14:20:24.204Z",
        "dateUpdated": "2026-05-12T11:50:59.992Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-21826 (GCVE-0-2025-21826)

    Vulnerability from cvelistv5 – Published: 2025-03-06 16:04 – Updated: 2026-08-05 11:54
    VLAI
    Title
    netfilter: nf_tables: reject mismatching sum of field_len with set key length
    Summary
    In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject mismatching sum of field_len with set key length The field length description provides the length of each separated key field in the concatenation, each field gets rounded up to 32-bits to calculate the pipapo rule width from pipapo_init(). The set key length provides the total size of the key aligned to 32-bits. Register-based arithmetics still allows for combining mismatching set key length and field length description, eg. set key length 10 and field description [ 5, 4 ] leading to pipapo width of 12.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 2d4c0798a1ef8db15b3277697ac2def4eda42312 , < 6b467c8feac759f4c5c86d708beca2aa2b29584f (git)
    Affected: 77be8c495a3f841e88b46508cc20d3d7d3289da3 , < 5083a7ae45003456c253e981b30a43f71230b4a3 (git)
    Affected: 9cb084df01e198119de477ac691d682fb01e80f3 , < 2ac254343d3cf228ae0738b2615fedf85d000752 (git)
    Affected: dc45bb00e66a33de1abb29e3d587880e1d4d9a7e , < 82e491e085719068179ff6a5466b7387cc4bbf32 (git)
    Affected: 3ce67e3793f48c1b9635beb9bb71116ca1e51b58 , < 49b7182b97bafbd5645414aff054b4a65d05823d (git)
    Affected: 3ce67e3793f48c1b9635beb9bb71116ca1e51b58 , < ab50d0eff4a939d20c37721fd9766347efcdb6f6 (git)
    Affected: 3ce67e3793f48c1b9635beb9bb71116ca1e51b58 , < 1b9335a8000fb70742f7db10af314104b6ace220 (git)
    Affected: ff67e3e488090908dc015ba04d7407d8bd467f7e (git)
    Affected: 5.10.209 , < 5.10.235 (semver)
    Affected: 5.15.148 , < 5.15.179 (semver)
    Affected: 6.1.75 , < 6.1.129 (semver)
    Affected: 6.6.14 , < 6.6.76 (semver)
    Affected: 6.7.2 , < 6.8 (semver)
    Create a notification for this product.
    Linux Linux Affected: 6.8
    Unaffected: 0 , < 6.8 (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.129 , ≤ 6.1.* (semver)
    Unaffected: 6.6.76 , ≤ 6.6.* (semver)
    Unaffected: 6.12.13 , ≤ 6.12.* (semver)
    Unaffected: 6.13.2 , ≤ 6.13.* (semver)
    Unaffected: 6.14 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:59:57.565Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:03:59.800Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/netfilter/nf_tables_api.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "6b467c8feac759f4c5c86d708beca2aa2b29584f",
                  "status": "affected",
                  "version": "2d4c0798a1ef8db15b3277697ac2def4eda42312",
                  "versionType": "git"
                },
                {
                  "lessThan": "5083a7ae45003456c253e981b30a43f71230b4a3",
                  "status": "affected",
                  "version": "77be8c495a3f841e88b46508cc20d3d7d3289da3",
                  "versionType": "git"
                },
                {
                  "lessThan": "2ac254343d3cf228ae0738b2615fedf85d000752",
                  "status": "affected",
                  "version": "9cb084df01e198119de477ac691d682fb01e80f3",
                  "versionType": "git"
                },
                {
                  "lessThan": "82e491e085719068179ff6a5466b7387cc4bbf32",
                  "status": "affected",
                  "version": "dc45bb00e66a33de1abb29e3d587880e1d4d9a7e",
                  "versionType": "git"
                },
                {
                  "lessThan": "49b7182b97bafbd5645414aff054b4a65d05823d",
                  "status": "affected",
                  "version": "3ce67e3793f48c1b9635beb9bb71116ca1e51b58",
                  "versionType": "git"
                },
                {
                  "lessThan": "ab50d0eff4a939d20c37721fd9766347efcdb6f6",
                  "status": "affected",
                  "version": "3ce67e3793f48c1b9635beb9bb71116ca1e51b58",
                  "versionType": "git"
                },
                {
                  "lessThan": "1b9335a8000fb70742f7db10af314104b6ace220",
                  "status": "affected",
                  "version": "3ce67e3793f48c1b9635beb9bb71116ca1e51b58",
                  "versionType": "git"
                },
                {
                  "status": "affected",
                  "version": "ff67e3e488090908dc015ba04d7407d8bd467f7e",
                  "versionType": "git"
                },
                {
                  "lessThan": "5.10.235",
                  "status": "affected",
                  "version": "5.10.209",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.15.179",
                  "status": "affected",
                  "version": "5.15.148",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.1.129",
                  "status": "affected",
                  "version": "6.1.75",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.6.76",
                  "status": "affected",
                  "version": "6.6.14",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.8",
                  "status": "affected",
                  "version": "6.7.2",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/netfilter/nf_tables_api.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.8"
                },
                {
                  "lessThan": "6.8",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.129",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.76",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.13",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.13.*",
                  "status": "unaffected",
                  "version": "6.13.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.14",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "5.10.209",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "5.15.148",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.129",
                      "versionStartIncluding": "6.1.75",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.76",
                      "versionStartIncluding": "6.6.14",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.13",
                      "versionStartIncluding": "6.8",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13.2",
                      "versionStartIncluding": "6.8",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.14",
                      "versionStartIncluding": "6.8",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionStartIncluding": "6.7.2",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: reject mismatching sum of field_len with set key length\n\nThe field length description provides the length of each separated key\nfield in the concatenation, each field gets rounded up to 32-bits to\ncalculate the pipapo rule width from pipapo_init(). The set key length\nprovides the total size of the key aligned to 32-bits.\n\nRegister-based arithmetics still allows for combining mismatching set\nkey length and field length description, eg. set key length 10 and field\ndescription [ 5, 4 ] leading to pipapo width of 12."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The vulnerability is reached exclusively through nfnetlink/netlink configuration messages to the nf_tables subsystem (NFT_MSG_NEWSET / NFT_MSG_NEWSETELEM), which require local system access. Per kernel scoring guidance, netfilter/nftables netlink paths are Local.\nAC:L - Triggering is fully deterministic and entirely attacker-controlled: create an interval+concat set with any key length not a multiple of 4 (e.g. klen=10 with field description [5,4]) and add one ranged element. No race, no memory-layout luck, and pipapo is the only backend that accepts multi-field interval sets so the vulnerable code is always selected.\nPR:L - nfnetlink_rcv_msg() checks netlink_net_capable(skb, CAP_NET_ADMIN), which is satisfied against the network namespace\u0027s owning user namespace, so any unprivileged local user can obtain it with `unshare -Urn` and then create the malformed set. This is the standard unprivileged-user-namespace path used by public nftables exploits.\nUI:N - The attacker performs all steps themselves through netlink; no victim action, mount, or file open is needed.\nS:U - The out-of-bounds accesses and the corrupted pipapo state remain within the kernel\u0027s own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - pipapo consumes round_up(klen,4) bytes from buffers holding only klen, reading past the end of the heap-allocated element extension (key_end) and consuming uninitialized kernel stack bytes from the on-stack struct nft_set_elem. Those out-of-bounds values are baked into the set\u0027s lookup tables and can be recovered by an attacker probing match results through the packet path, yielding kernel heap/stack disclosure.\nI:H - Kernel data structures (the pipapo lookup and mapping tables) are populated from memory outside the intended key object, so set state is corrupted with out-of-bounds content and packet-matching verdicts, maps, and NAT decisions become dependent on that data. Consistent with kernel-CNA precedent for local nftables/ebtables out-of-bounds accesses, the memory-safety violation is treated as High integrity impact.\nA:H - The slab out-of-bounds read past the element extension is a KASAN-reportable memory-safety violation that panics on hardened/panic_on_warn configurations and can fault when the object abuts an unmapped region, and the corrupted range endpoints drive pipapo_expand() rule expansion from garbage. Any such kernel crash is scored High."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:54:43.241Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/6b467c8feac759f4c5c86d708beca2aa2b29584f"
            },
            {
              "url": "https://git.kernel.org/stable/c/5083a7ae45003456c253e981b30a43f71230b4a3"
            },
            {
              "url": "https://git.kernel.org/stable/c/2ac254343d3cf228ae0738b2615fedf85d000752"
            },
            {
              "url": "https://git.kernel.org/stable/c/82e491e085719068179ff6a5466b7387cc4bbf32"
            },
            {
              "url": "https://git.kernel.org/stable/c/49b7182b97bafbd5645414aff054b4a65d05823d"
            },
            {
              "url": "https://git.kernel.org/stable/c/ab50d0eff4a939d20c37721fd9766347efcdb6f6"
            },
            {
              "url": "https://git.kernel.org/stable/c/1b9335a8000fb70742f7db10af314104b6ace220"
            }
          ],
          "title": "netfilter: nf_tables: reject mismatching sum of field_len with set key length",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2025-21826",
        "datePublished": "2025-03-06T16:04:32.274Z",
        "dateReserved": "2024-12-29T08:45:45.775Z",
        "dateUpdated": "2026-08-05T11:54:43.241Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-21806 (GCVE-0-2025-21806)

    Vulnerability from cvelistv5 – Published: 2025-02-27 20:00 – Updated: 2026-05-12 12:03
    VLAI
    Title
    net: let net.core.dev_weight always be non-zero
    Summary
    In the Linux kernel, the following vulnerability has been resolved: net: let net.core.dev_weight always be non-zero The following problem was encountered during stability test: (NULL net_device): NAPI poll function process_backlog+0x0/0x530 \ returned 1, exceeding its budget of 0. ------------[ cut here ]------------ list_add double add: new=ffff88905f746f48, prev=ffff88905f746f48, \ next=ffff88905f746e40. WARNING: CPU: 18 PID: 5462 at lib/list_debug.c:35 \ __list_add_valid_or_report+0xf3/0x130 CPU: 18 UID: 0 PID: 5462 Comm: ping Kdump: loaded Not tainted 6.13.0-rc7+ RIP: 0010:__list_add_valid_or_report+0xf3/0x130 Call Trace: ? __warn+0xcd/0x250 ? __list_add_valid_or_report+0xf3/0x130 enqueue_to_backlog+0x923/0x1070 netif_rx_internal+0x92/0x2b0 __netif_rx+0x15/0x170 loopback_xmit+0x2ef/0x450 dev_hard_start_xmit+0x103/0x490 __dev_queue_xmit+0xeac/0x1950 ip_finish_output2+0x6cc/0x1620 ip_output+0x161/0x270 ip_push_pending_frames+0x155/0x1a0 raw_sendmsg+0xe13/0x1550 __sys_sendto+0x3bf/0x4e0 __x64_sys_sendto+0xdc/0x1b0 do_syscall_64+0x5b/0x170 entry_SYSCALL_64_after_hwframe+0x76/0x7e The reproduction command is as follows: sysctl -w net.core.dev_weight=0 ping 127.0.0.1 This is because when the napi's weight is set to 0, process_backlog() may return 0 and clear the NAPI_STATE_SCHED bit of napi->state, causing this napi to be re-polled in net_rx_action() until __do_softirq() times out. Since the NAPI_STATE_SCHED bit has been cleared, napi_schedule_rps() can be retriggered in enqueue_to_backlog(), causing this issue. Making the napi's weight always non-zero solves this problem. Triggering this issue requires system-wide admin (setting is not namespaced).
    Severity
    No CVSS data available.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < d0e0f9c8218826926d7692980c98236d9f21fd3c (git)
    Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < c337c08819a4ec49edfdcd8fc46fbee120d8a5b2 (git)
    Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < 0e2f1d93d287d544d26f8ff293ea820a8079b9f8 (git)
    Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < 5860abbf15eeb61838b5e32e721ba67b0aa84450 (git)
    Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < 6ce38b5a6a49e65bad163162a54cb3f104c40b48 (git)
    Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < 33e2168788f8fb5cb8bd4f36cb1ef37d1d34dada (git)
    Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < 1489824e5226a26841c70639ebd2d1aed390764b (git)
    Affected: e3876605450979fe52a1a03e7eb78a89bf59e76a , < d1f9f79fa2af8e3b45cffdeef66e05833480148a (git)
    Create a notification for this product.
    Linux Linux Affected: 2.6.12
    Unaffected: 0 , < 2.6.12 (semver)
    Unaffected: 5.4.291 , ≤ 5.4.* (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.129 , ≤ 6.1.* (semver)
    Unaffected: 6.6.76 , ≤ 6.6.* (semver)
    Unaffected: 6.12.13 , ≤ 6.12.* (semver)
    Unaffected: 6.13.2 , ≤ 6.13.* (semver)
    Unaffected: 6.14 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:59:45.883Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:03:57.348Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/core/sysctl_net_core.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "d0e0f9c8218826926d7692980c98236d9f21fd3c",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                },
                {
                  "lessThan": "c337c08819a4ec49edfdcd8fc46fbee120d8a5b2",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                },
                {
                  "lessThan": "0e2f1d93d287d544d26f8ff293ea820a8079b9f8",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                },
                {
                  "lessThan": "5860abbf15eeb61838b5e32e721ba67b0aa84450",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                },
                {
                  "lessThan": "6ce38b5a6a49e65bad163162a54cb3f104c40b48",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                },
                {
                  "lessThan": "33e2168788f8fb5cb8bd4f36cb1ef37d1d34dada",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                },
                {
                  "lessThan": "1489824e5226a26841c70639ebd2d1aed390764b",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                },
                {
                  "lessThan": "d1f9f79fa2af8e3b45cffdeef66e05833480148a",
                  "status": "affected",
                  "version": "e3876605450979fe52a1a03e7eb78a89bf59e76a",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/core/sysctl_net_core.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.6.12"
                },
                {
                  "lessThan": "2.6.12",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.291",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.129",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.76",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.13",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.13.*",
                  "status": "unaffected",
                  "version": "6.13.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.14",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.291",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.129",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.76",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.13",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13.2",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.14",
                      "versionStartIncluding": "2.6.12",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: let net.core.dev_weight always be non-zero\n\nThe following problem was encountered during stability test:\n\n(NULL net_device): NAPI poll function process_backlog+0x0/0x530 \\\n\treturned 1, exceeding its budget of 0.\n------------[ cut here ]------------\nlist_add double add: new=ffff88905f746f48, prev=ffff88905f746f48, \\\n\tnext=ffff88905f746e40.\nWARNING: CPU: 18 PID: 5462 at lib/list_debug.c:35 \\\n\t__list_add_valid_or_report+0xf3/0x130\nCPU: 18 UID: 0 PID: 5462 Comm: ping Kdump: loaded Not tainted 6.13.0-rc7+\nRIP: 0010:__list_add_valid_or_report+0xf3/0x130\nCall Trace:\n? __warn+0xcd/0x250\n? __list_add_valid_or_report+0xf3/0x130\nenqueue_to_backlog+0x923/0x1070\nnetif_rx_internal+0x92/0x2b0\n__netif_rx+0x15/0x170\nloopback_xmit+0x2ef/0x450\ndev_hard_start_xmit+0x103/0x490\n__dev_queue_xmit+0xeac/0x1950\nip_finish_output2+0x6cc/0x1620\nip_output+0x161/0x270\nip_push_pending_frames+0x155/0x1a0\nraw_sendmsg+0xe13/0x1550\n__sys_sendto+0x3bf/0x4e0\n__x64_sys_sendto+0xdc/0x1b0\ndo_syscall_64+0x5b/0x170\nentry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nThe reproduction command is as follows:\n  sysctl -w net.core.dev_weight=0\n  ping 127.0.0.1\n\nThis is because when the napi\u0027s weight is set to 0, process_backlog() may\nreturn 0 and clear the NAPI_STATE_SCHED bit of napi-\u003estate, causing this\nnapi to be re-polled in net_rx_action() until __do_softirq() times out.\nSince the NAPI_STATE_SCHED bit has been cleared, napi_schedule_rps() can\nbe retriggered in enqueue_to_backlog(), causing this issue.\n\nMaking the napi\u0027s weight always non-zero solves this problem.\n\nTriggering this issue requires system-wide admin (setting is\nnot namespaced)."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T21:06:53.699Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/d0e0f9c8218826926d7692980c98236d9f21fd3c"
            },
            {
              "url": "https://git.kernel.org/stable/c/c337c08819a4ec49edfdcd8fc46fbee120d8a5b2"
            },
            {
              "url": "https://git.kernel.org/stable/c/0e2f1d93d287d544d26f8ff293ea820a8079b9f8"
            },
            {
              "url": "https://git.kernel.org/stable/c/5860abbf15eeb61838b5e32e721ba67b0aa84450"
            },
            {
              "url": "https://git.kernel.org/stable/c/6ce38b5a6a49e65bad163162a54cb3f104c40b48"
            },
            {
              "url": "https://git.kernel.org/stable/c/33e2168788f8fb5cb8bd4f36cb1ef37d1d34dada"
            },
            {
              "url": "https://git.kernel.org/stable/c/1489824e5226a26841c70639ebd2d1aed390764b"
            },
            {
              "url": "https://git.kernel.org/stable/c/d1f9f79fa2af8e3b45cffdeef66e05833480148a"
            }
          ],
          "title": "net: let net.core.dev_weight always be non-zero",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2025-21806",
        "datePublished": "2025-02-27T20:00:58.918Z",
        "dateReserved": "2024-12-29T08:45:45.771Z",
        "dateUpdated": "2026-05-12T12:03:57.348Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-21776 (GCVE-0-2025-21776)

    Vulnerability from cvelistv5 – Published: 2025-02-27 02:18 – Updated: 2026-05-12 12:03
    VLAI
    Title
    USB: hub: Ignore non-compliant devices with too many configs or interfaces
    Summary
    In the Linux kernel, the following vulnerability has been resolved: USB: hub: Ignore non-compliant devices with too many configs or interfaces Robert Morris created a test program which can cause usb_hub_to_struct_hub() to dereference a NULL or inappropriate pointer: Oops: general protection fault, probably for non-canonical address 0xcccccccccccccccc: 0000 [#1] SMP DEBUG_PAGEALLOC PTI CPU: 7 UID: 0 PID: 117 Comm: kworker/7:1 Not tainted 6.13.0-rc3-00017-gf44d154d6e3d #14 Hardware name: FreeBSD BHYVE/BHYVE, BIOS 14.0 10/17/2021 Workqueue: usb_hub_wq hub_event RIP: 0010:usb_hub_adjust_deviceremovable+0x78/0x110 ... Call Trace: <TASK> ? die_addr+0x31/0x80 ? exc_general_protection+0x1b4/0x3c0 ? asm_exc_general_protection+0x26/0x30 ? usb_hub_adjust_deviceremovable+0x78/0x110 hub_probe+0x7c7/0xab0 usb_probe_interface+0x14b/0x350 really_probe+0xd0/0x2d0 ? __pfx___device_attach_driver+0x10/0x10 __driver_probe_device+0x6e/0x110 driver_probe_device+0x1a/0x90 __device_attach_driver+0x7e/0xc0 bus_for_each_drv+0x7f/0xd0 __device_attach+0xaa/0x1a0 bus_probe_device+0x8b/0xa0 device_add+0x62e/0x810 usb_set_configuration+0x65d/0x990 usb_generic_driver_probe+0x4b/0x70 usb_probe_device+0x36/0xd0 The cause of this error is that the device has two interfaces, and the hub driver binds to interface 1 instead of interface 0, which is where usb_hub_to_struct_hub() looks. We can prevent the problem from occurring by refusing to accept hub devices that violate the USB spec by having more than one configuration or interface.
    Severity
    No CVSS data available.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < 49f077106fa07919a6a6dda99bb490dd1d1a8218 (git)
    Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < d343fe0fad5c1d689775f2dda24a85ce98e29566 (git)
    Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < d3a67adb365cdfdac4620daf38a82e57ca45806c (git)
    Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < c3720b04df84b5459050ae4e03ec7d545652f897 (git)
    Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < e905a0fca7bff0855d312c16f71e60e1773b393e (git)
    Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < 62d8f4c5454dd39aded4f343720d1c5a1803cfef (git)
    Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < 5b9778e1fe715700993ce436c152dc3b7df0b490 (git)
    Affected: d2123fd9e1a56b8006986ed37e0aaf93ef0dd978 , < 2240fed37afbcdb5e8b627bc7ad986891100e05d (git)
    Create a notification for this product.
    Linux Linux Affected: 3.9
    Unaffected: 0 , < 3.9 (semver)
    Unaffected: 5.4.291 , ≤ 5.4.* (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.129 , ≤ 6.1.* (semver)
    Unaffected: 6.6.79 , ≤ 6.6.* (semver)
    Unaffected: 6.12.16 , ≤ 6.12.* (semver)
    Unaffected: 6.13.4 , ≤ 6.13.* (semver)
    Unaffected: 6.14 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:37:31.434Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:03:52.412Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/usb/core/hub.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "49f077106fa07919a6a6dda99bb490dd1d1a8218",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                },
                {
                  "lessThan": "d343fe0fad5c1d689775f2dda24a85ce98e29566",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                },
                {
                  "lessThan": "d3a67adb365cdfdac4620daf38a82e57ca45806c",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                },
                {
                  "lessThan": "c3720b04df84b5459050ae4e03ec7d545652f897",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                },
                {
                  "lessThan": "e905a0fca7bff0855d312c16f71e60e1773b393e",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                },
                {
                  "lessThan": "62d8f4c5454dd39aded4f343720d1c5a1803cfef",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                },
                {
                  "lessThan": "5b9778e1fe715700993ce436c152dc3b7df0b490",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                },
                {
                  "lessThan": "2240fed37afbcdb5e8b627bc7ad986891100e05d",
                  "status": "affected",
                  "version": "d2123fd9e1a56b8006986ed37e0aaf93ef0dd978",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/usb/core/hub.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.9"
                },
                {
                  "lessThan": "3.9",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.291",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.129",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.79",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.16",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.13.*",
                  "status": "unaffected",
                  "version": "6.13.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.14",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.291",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.129",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.79",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.16",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13.4",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.14",
                      "versionStartIncluding": "3.9",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: hub: Ignore non-compliant devices with too many configs or interfaces\n\nRobert Morris created a test program which can cause\nusb_hub_to_struct_hub() to dereference a NULL or inappropriate\npointer:\n\nOops: general protection fault, probably for non-canonical address\n0xcccccccccccccccc: 0000 [#1] SMP DEBUG_PAGEALLOC PTI\nCPU: 7 UID: 0 PID: 117 Comm: kworker/7:1 Not tainted 6.13.0-rc3-00017-gf44d154d6e3d #14\nHardware name: FreeBSD BHYVE/BHYVE, BIOS 14.0 10/17/2021\nWorkqueue: usb_hub_wq hub_event\nRIP: 0010:usb_hub_adjust_deviceremovable+0x78/0x110\n...\nCall Trace:\n \u003cTASK\u003e\n ? die_addr+0x31/0x80\n ? exc_general_protection+0x1b4/0x3c0\n ? asm_exc_general_protection+0x26/0x30\n ? usb_hub_adjust_deviceremovable+0x78/0x110\n hub_probe+0x7c7/0xab0\n usb_probe_interface+0x14b/0x350\n really_probe+0xd0/0x2d0\n ? __pfx___device_attach_driver+0x10/0x10\n __driver_probe_device+0x6e/0x110\n driver_probe_device+0x1a/0x90\n __device_attach_driver+0x7e/0xc0\n bus_for_each_drv+0x7f/0xd0\n __device_attach+0xaa/0x1a0\n bus_probe_device+0x8b/0xa0\n device_add+0x62e/0x810\n usb_set_configuration+0x65d/0x990\n usb_generic_driver_probe+0x4b/0x70\n usb_probe_device+0x36/0xd0\n\nThe cause of this error is that the device has two interfaces, and the\nhub driver binds to interface 1 instead of interface 0, which is where\nusb_hub_to_struct_hub() looks.\n\nWe can prevent the problem from occurring by refusing to accept hub\ndevices that violate the USB spec by having more than one\nconfiguration or interface."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T21:06:12.467Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/49f077106fa07919a6a6dda99bb490dd1d1a8218"
            },
            {
              "url": "https://git.kernel.org/stable/c/d343fe0fad5c1d689775f2dda24a85ce98e29566"
            },
            {
              "url": "https://git.kernel.org/stable/c/d3a67adb365cdfdac4620daf38a82e57ca45806c"
            },
            {
              "url": "https://git.kernel.org/stable/c/c3720b04df84b5459050ae4e03ec7d545652f897"
            },
            {
              "url": "https://git.kernel.org/stable/c/e905a0fca7bff0855d312c16f71e60e1773b393e"
            },
            {
              "url": "https://git.kernel.org/stable/c/62d8f4c5454dd39aded4f343720d1c5a1803cfef"
            },
            {
              "url": "https://git.kernel.org/stable/c/5b9778e1fe715700993ce436c152dc3b7df0b490"
            },
            {
              "url": "https://git.kernel.org/stable/c/2240fed37afbcdb5e8b627bc7ad986891100e05d"
            }
          ],
          "title": "USB: hub: Ignore non-compliant devices with too many configs or interfaces",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2025-21776",
        "datePublished": "2025-02-27T02:18:21.503Z",
        "dateReserved": "2024-12-29T08:45:45.763Z",
        "dateUpdated": "2026-05-12T12:03:52.412Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-21762 (GCVE-0-2025-21762)

    Vulnerability from cvelistv5 – Published: 2025-02-27 02:18 – Updated: 2026-08-05 11:54
    VLAI
    Title
    arp: use RCU protection in arp_xmit()
    Summary
    In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() can be called without RTNL or RCU protection. Use RCU protection to avoid potential UAF.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-02-27 17:57 UTC
    CWE
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < 10f555e3f573d004ae9d89b3276abb58c4ede5c3 (git)
    Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < 307cd1e2d3cb1cbc6c40c679cada6d7168b18431 (git)
    Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < d9366ac2f956a1948b68c0500f84a3462ff2ed8a (git)
    Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < f189654459423d4d48bef2d120b4bfba559e6039 (git)
    Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < e9f4dee534eb1b225b0a120395ad9bc2afe164d3 (git)
    Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < 01d1b5c9abcaff29a43f1d17a19c33eec92c7dbe (git)
    Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < 2c331718d3389b6c5f6855078ab7171849e016bd (git)
    Affected: 29a26a56803855a79dbd028cd61abee56237d6e5 , < a42b69f692165ec39db42d595f4f65a4c8f42e44 (git)
    Create a notification for this product.
    Linux Linux Affected: 4.4
    Unaffected: 0 , < 4.4 (semver)
    Unaffected: 5.4.291 , ≤ 5.4.* (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.129 , ≤ 6.1.* (semver)
    Unaffected: 6.6.79 , ≤ 6.6.* (semver)
    Unaffected: 6.12.16 , ≤ 6.12.* (semver)
    Unaffected: 6.13.4 , ≤ 6.13.* (semver)
    Unaffected: 6.14 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "LOCAL",
                  "availabilityImpact": "HIGH",
                  "baseScore": 7.8,
                  "baseSeverity": "HIGH",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "LOW",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-21762",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-02-27T17:57:30.024595Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-416",
                    "description": "CWE-416 Use After Free",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-02-27T18:02:27.083Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:37:11.540Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:03:43.118Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/ipv4/arp.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "10f555e3f573d004ae9d89b3276abb58c4ede5c3",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                },
                {
                  "lessThan": "307cd1e2d3cb1cbc6c40c679cada6d7168b18431",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                },
                {
                  "lessThan": "d9366ac2f956a1948b68c0500f84a3462ff2ed8a",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                },
                {
                  "lessThan": "f189654459423d4d48bef2d120b4bfba559e6039",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                },
                {
                  "lessThan": "e9f4dee534eb1b225b0a120395ad9bc2afe164d3",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                },
                {
                  "lessThan": "01d1b5c9abcaff29a43f1d17a19c33eec92c7dbe",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                },
                {
                  "lessThan": "2c331718d3389b6c5f6855078ab7171849e016bd",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                },
                {
                  "lessThan": "a42b69f692165ec39db42d595f4f65a4c8f42e44",
                  "status": "affected",
                  "version": "29a26a56803855a79dbd028cd61abee56237d6e5",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/ipv4/arp.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.4"
                },
                {
                  "lessThan": "4.4",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.291",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.129",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.79",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.16",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.13.*",
                  "status": "unaffected",
                  "version": "6.13.4",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.14",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.291",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.129",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.79",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.16",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13.4",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.14",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\narp: use RCU protection in arp_xmit()\n\narp_xmit() can be called without RTNL or RCU protection.\n\nUse RCU protection to avoid potential UAF."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:N - The unprotected `arp_xmit()` calls are driven by the neighbour-resolution path (`neigh_timer_handler` \u2192 `neigh_probe` \u2192 `arp_solicit`), which a remote off-link attacker triggers at will by sending traffic to a Linux router/gateway that must resolve on-link next hops, as well as by ARP frames processed in `arp_process()`/bridge neigh-suppression. The vulnerable code is bound to the network stack and reachable from remotely originated packets, so Network is the correct and higher-severity classification.\nAC:H - The attacker fully controls and can sustain the ARP-transmit side of the race, but the other side \u2014 a `struct net` being freed via `cleanup_net()` or a device migrating namespaces \u2014 is background system activity the network attacker cannot command. Because that condition lies outside attacker control, complexity is High.\nPR:N - There is no capability check, credential check, or authentication gate anywhere on the path from packet receipt/neighbour resolution to `arp_xmit()`; ARP solicitation and reply generation happen unconditionally in softirq context. An entirely unauthenticated attacker reaches the vulnerable code.\nUI:N - The attacker\u0027s own packets cause the kernel to emit ARP and execute the vulnerable code; no victim must mount a filesystem, open a file, or take any other action.\nS:U - The use-after-free of `struct net` and the resulting corruption stay entirely within the kernel\u0027s own security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - A use-after-free of `struct net` lets `nf_hook()` read `net-\u003enf.hooks_arp[]` and every ARP-family hook read `state-\u003enet` out of freed, potentially reallocated slab memory. Per kernel guidance a UAF gives the attacker control over the freed object\u0027s contents and thus an arbitrary kernel-memory read primitive.\nI:H - The stale `net` yields a `hook_head` pointer from freed memory, and `nf_hook_slow()` then performs an indirect call through `e-\u003ehooks[s].hook` \u2014 a direct function-pointer hijack primitive if the netns slab is reallocated with sprayed data. Hooks also write through `state-\u003enet`, corrupting reused kernel objects.\nA:H - Dereferencing a freed `struct net` and calling through a garbage `nf_hook_entries` reliably oopses or panics the kernel, and is a KASAN-reportable memory-safety violation that panics on hardened configurations. Any such kernel crash is scored High."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:54:15.248Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/10f555e3f573d004ae9d89b3276abb58c4ede5c3"
            },
            {
              "url": "https://git.kernel.org/stable/c/307cd1e2d3cb1cbc6c40c679cada6d7168b18431"
            },
            {
              "url": "https://git.kernel.org/stable/c/d9366ac2f956a1948b68c0500f84a3462ff2ed8a"
            },
            {
              "url": "https://git.kernel.org/stable/c/f189654459423d4d48bef2d120b4bfba559e6039"
            },
            {
              "url": "https://git.kernel.org/stable/c/e9f4dee534eb1b225b0a120395ad9bc2afe164d3"
            },
            {
              "url": "https://git.kernel.org/stable/c/01d1b5c9abcaff29a43f1d17a19c33eec92c7dbe"
            },
            {
              "url": "https://git.kernel.org/stable/c/2c331718d3389b6c5f6855078ab7171849e016bd"
            },
            {
              "url": "https://git.kernel.org/stable/c/a42b69f692165ec39db42d595f4f65a4c8f42e44"
            }
          ],
          "title": "arp: use RCU protection in arp_xmit()",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2025-21762",
        "datePublished": "2025-02-27T02:18:14.600Z",
        "dateReserved": "2024-12-29T08:45:45.761Z",
        "dateUpdated": "2026-08-05T11:54:15.248Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-58005 (GCVE-0-2024-58005)

    Vulnerability from cvelistv5 – Published: 2025-02-27 02:12 – Updated: 2026-07-14 12:38
    VLAI
    Title
    tpm: Change to kvalloc() in eventlog/acpi.c
    Summary
    In the Linux kernel, the following vulnerability has been resolved: tpm: Change to kvalloc() in eventlog/acpi.c The following failure was reported on HPE ProLiant D320: [ 10.693310][ T1] tpm_tis STM0925:00: 2.0 TPM (device-id 0x3, rev-id 0) [ 10.848132][ T1] ------------[ cut here ]------------ [ 10.853559][ T1] WARNING: CPU: 59 PID: 1 at mm/page_alloc.c:4727 __alloc_pages_noprof+0x2ca/0x330 [ 10.862827][ T1] Modules linked in: [ 10.866671][ T1] CPU: 59 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.0-lp155.2.g52785e2-default #1 openSUSE Tumbleweed (unreleased) 588cd98293a7c9eba9013378d807364c088c9375 [ 10.882741][ T1] Hardware name: HPE ProLiant DL320 Gen12/ProLiant DL320 Gen12, BIOS 1.20 10/28/2024 [ 10.892170][ T1] RIP: 0010:__alloc_pages_noprof+0x2ca/0x330 [ 10.898103][ T1] Code: 24 08 e9 4a fe ff ff e8 34 36 fa ff e9 88 fe ff ff 83 fe 0a 0f 86 b3 fd ff ff 80 3d 01 e7 ce 01 00 75 09 c6 05 f8 e6 ce 01 01 <0f> 0b 45 31 ff e9 e5 fe ff ff f7 c2 00 00 08 00 75 42 89 d9 80 e1 [ 10.917750][ T1] RSP: 0000:ffffb7cf40077980 EFLAGS: 00010246 [ 10.923777][ T1] RAX: 0000000000000000 RBX: 0000000000040cc0 RCX: 0000000000000000 [ 10.931727][ T1] RDX: 0000000000000000 RSI: 000000000000000c RDI: 0000000000040cc0 The above transcript shows that ACPI pointed a 16 MiB buffer for the log events because RSI maps to the 'order' parameter of __alloc_pages_noprof(). Address the bug by moving from devm_kmalloc() to devm_add_action() and kvmalloc() and devm_add_action().
    Severity
    No CVSS data available.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 55a82ab3181be039c6440d3f2f69260ad6fe2988 , < a676c0401de59548a5bc1b7aaf98f556ae8ea6db (git)
    Affected: 55a82ab3181be039c6440d3f2f69260ad6fe2988 , < 0621d2599d6e02d05c85d6bbd58eaea2f15b3503 (git)
    Affected: 55a82ab3181be039c6440d3f2f69260ad6fe2988 , < 77779d1258a287f2c5c2c6aeae203e0996209c77 (git)
    Affected: 55a82ab3181be039c6440d3f2f69260ad6fe2988 , < 50365a6304a57266e8f4d3078060743c3b7a1e0d (git)
    Affected: 55a82ab3181be039c6440d3f2f69260ad6fe2988 , < 422d7f4e8d817be467986589c7968d3ea402f7da (git)
    Affected: 55a82ab3181be039c6440d3f2f69260ad6fe2988 , < 4c8bfe643bbd00b04ee8f9545ef33bf6a68c38db (git)
    Affected: 55a82ab3181be039c6440d3f2f69260ad6fe2988 , < a3a860bc0fd6c07332e4911cf9a238d20de90173 (git)
    Create a notification for this product.
    Linux Linux Affected: 2.6.16
    Unaffected: 0 , < 2.6.16 (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.130 , ≤ 6.1.* (semver)
    Unaffected: 6.6.78 , ≤ 6.6.* (semver)
    Unaffected: 6.12.14 , ≤ 6.12.* (semver)
    Unaffected: 6.13.3 , ≤ 6.13.* (semver)
    Unaffected: 6.14 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.5 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP Affected: V3.1.5 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.5 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:33:18.687Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.5",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-14T12:38:49.969Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/char/tpm/eventlog/acpi.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "a676c0401de59548a5bc1b7aaf98f556ae8ea6db",
                  "status": "affected",
                  "version": "55a82ab3181be039c6440d3f2f69260ad6fe2988",
                  "versionType": "git"
                },
                {
                  "lessThan": "0621d2599d6e02d05c85d6bbd58eaea2f15b3503",
                  "status": "affected",
                  "version": "55a82ab3181be039c6440d3f2f69260ad6fe2988",
                  "versionType": "git"
                },
                {
                  "lessThan": "77779d1258a287f2c5c2c6aeae203e0996209c77",
                  "status": "affected",
                  "version": "55a82ab3181be039c6440d3f2f69260ad6fe2988",
                  "versionType": "git"
                },
                {
                  "lessThan": "50365a6304a57266e8f4d3078060743c3b7a1e0d",
                  "status": "affected",
                  "version": "55a82ab3181be039c6440d3f2f69260ad6fe2988",
                  "versionType": "git"
                },
                {
                  "lessThan": "422d7f4e8d817be467986589c7968d3ea402f7da",
                  "status": "affected",
                  "version": "55a82ab3181be039c6440d3f2f69260ad6fe2988",
                  "versionType": "git"
                },
                {
                  "lessThan": "4c8bfe643bbd00b04ee8f9545ef33bf6a68c38db",
                  "status": "affected",
                  "version": "55a82ab3181be039c6440d3f2f69260ad6fe2988",
                  "versionType": "git"
                },
                {
                  "lessThan": "a3a860bc0fd6c07332e4911cf9a238d20de90173",
                  "status": "affected",
                  "version": "55a82ab3181be039c6440d3f2f69260ad6fe2988",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/char/tpm/eventlog/acpi.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.6.16"
                },
                {
                  "lessThan": "2.6.16",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.130",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.78",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.14",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.13.*",
                  "status": "unaffected",
                  "version": "6.13.3",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.14",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "2.6.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "2.6.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.130",
                      "versionStartIncluding": "2.6.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.78",
                      "versionStartIncluding": "2.6.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.14",
                      "versionStartIncluding": "2.6.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13.3",
                      "versionStartIncluding": "2.6.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.14",
                      "versionStartIncluding": "2.6.16",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ntpm: Change to kvalloc() in eventlog/acpi.c\n\nThe following failure was reported on HPE ProLiant D320:\n\n[   10.693310][    T1] tpm_tis STM0925:00: 2.0 TPM (device-id 0x3, rev-id 0)\n[   10.848132][    T1] ------------[ cut here ]------------\n[   10.853559][    T1] WARNING: CPU: 59 PID: 1 at mm/page_alloc.c:4727 __alloc_pages_noprof+0x2ca/0x330\n[   10.862827][    T1] Modules linked in:\n[   10.866671][    T1] CPU: 59 UID: 0 PID: 1 Comm: swapper/0 Not tainted 6.12.0-lp155.2.g52785e2-default #1 openSUSE Tumbleweed (unreleased) 588cd98293a7c9eba9013378d807364c088c9375\n[   10.882741][    T1] Hardware name: HPE ProLiant DL320 Gen12/ProLiant DL320 Gen12, BIOS 1.20 10/28/2024\n[   10.892170][    T1] RIP: 0010:__alloc_pages_noprof+0x2ca/0x330\n[   10.898103][    T1] Code: 24 08 e9 4a fe ff ff e8 34 36 fa ff e9 88 fe ff ff 83 fe 0a 0f 86 b3 fd ff ff 80 3d 01 e7 ce 01 00 75 09 c6 05 f8 e6 ce 01 01 \u003c0f\u003e 0b 45 31 ff e9 e5 fe ff ff f7 c2 00 00 08 00 75 42 89 d9 80 e1\n[   10.917750][    T1] RSP: 0000:ffffb7cf40077980 EFLAGS: 00010246\n[   10.923777][    T1] RAX: 0000000000000000 RBX: 0000000000040cc0 RCX: 0000000000000000\n[   10.931727][    T1] RDX: 0000000000000000 RSI: 000000000000000c RDI: 0000000000040cc0\n\nThe above transcript shows that ACPI pointed a 16 MiB buffer for the log\nevents because RSI maps to the \u0027order\u0027 parameter of __alloc_pages_noprof().\nAddress the bug by moving from devm_kmalloc() to devm_add_action() and\nkvmalloc() and devm_add_action()."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T21:01:57.391Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/a676c0401de59548a5bc1b7aaf98f556ae8ea6db"
            },
            {
              "url": "https://git.kernel.org/stable/c/0621d2599d6e02d05c85d6bbd58eaea2f15b3503"
            },
            {
              "url": "https://git.kernel.org/stable/c/77779d1258a287f2c5c2c6aeae203e0996209c77"
            },
            {
              "url": "https://git.kernel.org/stable/c/50365a6304a57266e8f4d3078060743c3b7a1e0d"
            },
            {
              "url": "https://git.kernel.org/stable/c/422d7f4e8d817be467986589c7968d3ea402f7da"
            },
            {
              "url": "https://git.kernel.org/stable/c/4c8bfe643bbd00b04ee8f9545ef33bf6a68c38db"
            },
            {
              "url": "https://git.kernel.org/stable/c/a3a860bc0fd6c07332e4911cf9a238d20de90173"
            }
          ],
          "title": "tpm: Change to kvalloc() in eventlog/acpi.c",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-58005",
        "datePublished": "2025-02-27T02:12:02.232Z",
        "dateReserved": "2025-02-27T02:10:48.226Z",
        "dateUpdated": "2026-07-14T12:38:49.969Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-57981 (GCVE-0-2024-57981)

    Vulnerability from cvelistv5 – Published: 2025-02-27 02:07 – Updated: 2026-05-12 12:01
    VLAI
    Title
    usb: xhci: Fix NULL pointer dereference on certain command aborts
    Summary
    In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix NULL pointer dereference on certain command aborts If a command is queued to the final usable TRB of a ring segment, the enqueue pointer is advanced to the subsequent link TRB and no further. If the command is later aborted, when the abort completion is handled the dequeue pointer is advanced to the first TRB of the next segment. If no further commands are queued, xhci_handle_stopped_cmd_ring() sees the ring pointers unequal and assumes that there is a pending command, so it calls xhci_mod_cmd_timer() which crashes if cur_cmd was NULL. Don't attempt timer setup if cur_cmd is NULL. The subsequent doorbell ring likely is unnecessary too, but it's harmless. Leave it alone. This is probably Bug 219532, but no confirmation has been received. The issue has been independently reproduced and confirmed fixed using a USB MCU programmed to NAK the Status stage of SET_ADDRESS forever. Everything continued working normally after several prevented crashes.
    Severity
    No CVSS data available.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: c311e391a7efd101250c0e123286709b7e736249 , < fd8bfaeba4a85b14427899adec0efb3954300653 (git)
    Affected: c311e391a7efd101250c0e123286709b7e736249 , < b44253956407046e5907d4d72c8fa5b93ae94485 (git)
    Affected: c311e391a7efd101250c0e123286709b7e736249 , < cf30300a216a4f8dce94e11781a866a09d4b50d4 (git)
    Affected: c311e391a7efd101250c0e123286709b7e736249 , < 4ff18870af793ce2034a6ad746e91d0a3d985b88 (git)
    Affected: c311e391a7efd101250c0e123286709b7e736249 , < b649f0d5bc256f691c7d234c3986685d54053de1 (git)
    Affected: c311e391a7efd101250c0e123286709b7e736249 , < ae069cd2ba09a2bd6a87a68c59ef0b7ea39cd641 (git)
    Affected: c311e391a7efd101250c0e123286709b7e736249 , < 0ce5c0dac768be14afe2426101b568a0f66bfc4d (git)
    Affected: c311e391a7efd101250c0e123286709b7e736249 , < 1e0a19912adb68a4b2b74fd77001c96cd83eb073 (git)
    Create a notification for this product.
    Linux Linux Affected: 3.16
    Unaffected: 0 , < 3.16 (semver)
    Unaffected: 5.4.291 , ≤ 5.4.* (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.129 , ≤ 6.1.* (semver)
    Unaffected: 6.6.76 , ≤ 6.6.* (semver)
    Unaffected: 6.12.13 , ≤ 6.12.* (semver)
    Unaffected: 6.13.2 , ≤ 6.13.* (semver)
    Unaffected: 6.14 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T19:33:02.039Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:01:46.491Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/usb/host/xhci-ring.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "fd8bfaeba4a85b14427899adec0efb3954300653",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                },
                {
                  "lessThan": "b44253956407046e5907d4d72c8fa5b93ae94485",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                },
                {
                  "lessThan": "cf30300a216a4f8dce94e11781a866a09d4b50d4",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                },
                {
                  "lessThan": "4ff18870af793ce2034a6ad746e91d0a3d985b88",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                },
                {
                  "lessThan": "b649f0d5bc256f691c7d234c3986685d54053de1",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                },
                {
                  "lessThan": "ae069cd2ba09a2bd6a87a68c59ef0b7ea39cd641",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                },
                {
                  "lessThan": "0ce5c0dac768be14afe2426101b568a0f66bfc4d",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                },
                {
                  "lessThan": "1e0a19912adb68a4b2b74fd77001c96cd83eb073",
                  "status": "affected",
                  "version": "c311e391a7efd101250c0e123286709b7e736249",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/usb/host/xhci-ring.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.16"
                },
                {
                  "lessThan": "3.16",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.291",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.129",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.76",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.13",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.13.*",
                  "status": "unaffected",
                  "version": "6.13.2",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.14",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.291",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.129",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.76",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.13",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13.2",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.14",
                      "versionStartIncluding": "3.16",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nusb: xhci: Fix NULL pointer dereference on certain command aborts\n\nIf a command is queued to the final usable TRB of a ring segment, the\nenqueue pointer is advanced to the subsequent link TRB and no further.\nIf the command is later aborted, when the abort completion is handled\nthe dequeue pointer is advanced to the first TRB of the next segment.\n\nIf no further commands are queued, xhci_handle_stopped_cmd_ring() sees\nthe ring pointers unequal and assumes that there is a pending command,\nso it calls xhci_mod_cmd_timer() which crashes if cur_cmd was NULL.\n\nDon\u0027t attempt timer setup if cur_cmd is NULL. The subsequent doorbell\nring likely is unnecessary too, but it\u0027s harmless. Leave it alone.\n\nThis is probably Bug 219532, but no confirmation has been received.\n\nThe issue has been independently reproduced and confirmed fixed using\na USB MCU programmed to NAK the Status stage of SET_ADDRESS forever.\nEverything continued working normally after several prevented crashes."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T21:01:29.822Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/fd8bfaeba4a85b14427899adec0efb3954300653"
            },
            {
              "url": "https://git.kernel.org/stable/c/b44253956407046e5907d4d72c8fa5b93ae94485"
            },
            {
              "url": "https://git.kernel.org/stable/c/cf30300a216a4f8dce94e11781a866a09d4b50d4"
            },
            {
              "url": "https://git.kernel.org/stable/c/4ff18870af793ce2034a6ad746e91d0a3d985b88"
            },
            {
              "url": "https://git.kernel.org/stable/c/b649f0d5bc256f691c7d234c3986685d54053de1"
            },
            {
              "url": "https://git.kernel.org/stable/c/ae069cd2ba09a2bd6a87a68c59ef0b7ea39cd641"
            },
            {
              "url": "https://git.kernel.org/stable/c/0ce5c0dac768be14afe2426101b568a0f66bfc4d"
            },
            {
              "url": "https://git.kernel.org/stable/c/1e0a19912adb68a4b2b74fd77001c96cd83eb073"
            }
          ],
          "title": "usb: xhci: Fix NULL pointer dereference on certain command aborts",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-57981",
        "datePublished": "2025-02-27T02:07:07.489Z",
        "dateReserved": "2025-02-27T02:04:28.913Z",
        "dateUpdated": "2026-05-12T12:01:46.491Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-21678 (GCVE-0-2025-21678)

    Vulnerability from cvelistv5 – Published: 2025-01-31 11:25 – Updated: 2026-08-05 11:53
    VLAI
    Title
    gtp: Destroy device along with udp socket's netns dismantle.
    Summary
    In the Linux kernel, the following vulnerability has been resolved: gtp: Destroy device along with udp socket's netns dismantle. gtp_newlink() links the device to a list in dev_net(dev) instead of src_net, where a udp tunnel socket is created. Even when src_net is removed, the device stays alive on dev_net(dev). Then, removing src_net triggers the splat below. [0] In this example, gtp0 is created in ns2, and the udp socket is created in ns1. ip netns add ns1 ip netns add ns2 ip -n ns1 link add netns ns2 name gtp0 type gtp role sgsn ip netns del ns1 Let's link the device to the socket's netns instead. Now, gtp_net_exit_batch_rtnl() needs another netdev iteration to remove all gtp devices in the netns. [0]: ref_tracker: net notrefcnt@000000003d6e7d05 has 1/2 users at sk_alloc (./include/net/net_namespace.h:345 net/core/sock.c:2236) inet_create (net/ipv4/af_inet.c:326 net/ipv4/af_inet.c:252) __sock_create (net/socket.c:1558) udp_sock_create4 (net/ipv4/udp_tunnel_core.c:18) gtp_create_sock (./include/net/udp_tunnel.h:59 drivers/net/gtp.c:1423) gtp_create_sockets (drivers/net/gtp.c:1447) gtp_newlink (drivers/net/gtp.c:1507) rtnl_newlink (net/core/rtnetlink.c:3786 net/core/rtnetlink.c:3897 net/core/rtnetlink.c:4012) rtnetlink_rcv_msg (net/core/rtnetlink.c:6922) netlink_rcv_skb (net/netlink/af_netlink.c:2542) netlink_unicast (net/netlink/af_netlink.c:1321 net/netlink/af_netlink.c:1347) netlink_sendmsg (net/netlink/af_netlink.c:1891) ____sys_sendmsg (net/socket.c:711 net/socket.c:726 net/socket.c:2583) ___sys_sendmsg (net/socket.c:2639) __sys_sendmsg (net/socket.c:2669) do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83) WARNING: CPU: 1 PID: 60 at lib/ref_tracker.c:179 ref_tracker_dir_exit (lib/ref_tracker.c:179) Modules linked in: CPU: 1 UID: 0 PID: 60 Comm: kworker/u16:2 Not tainted 6.13.0-rc5-00147-g4c1224501e9d #5 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 Workqueue: netns cleanup_net RIP: 0010:ref_tracker_dir_exit (lib/ref_tracker.c:179) Code: 00 00 00 fc ff df 4d 8b 26 49 bd 00 01 00 00 00 00 ad de 4c 39 f5 0f 85 df 00 00 00 48 8b 74 24 08 48 89 df e8 a5 cc 12 02 90 <0f> 0b 90 48 8d 6b 44 be 04 00 00 00 48 89 ef e8 80 de 67 ff 48 89 RSP: 0018:ff11000009a07b60 EFLAGS: 00010286 RAX: 0000000000002bd3 RBX: ff1100000f4e1aa0 RCX: 1ffffffff0e40ac6 RDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff8423ee3c RBP: ff1100000f4e1af0 R08: 0000000000000001 R09: fffffbfff0e395ae R10: 0000000000000001 R11: 0000000000036001 R12: ff1100000f4e1af0 R13: dead000000000100 R14: ff1100000f4e1af0 R15: dffffc0000000000 FS: 0000000000000000(0000) GS:ff1100006ce80000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f9b2464bd98 CR3: 0000000005286005 CR4: 0000000000771ef0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400 PKRU: 55555554 Call Trace: <TASK> ? __warn (kernel/panic.c:748) ? ref_tracker_dir_exit (lib/ref_tracker.c:179) ? report_bug (lib/bug.c:201 lib/bug.c:219) ? handle_bug (arch/x86/kernel/traps.c:285) ? exc_invalid_op (arch/x86/kernel/traps.c:309 (discriminator 1)) ? asm_exc_invalid_op (./arch/x86/include/asm/idtentry.h:621) ? _raw_spin_unlock_irqrestore (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:97 ./arch/x86/include/asm/irqflags.h:155 ./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194) ? ref_tracker_dir_exit (lib/ref_tracker.c:179) ? __pfx_ref_tracker_dir_exit (lib/ref_tracker.c:158) ? kfree (mm/slub.c:4613 mm/slub.c:4761) net_free (net/core/net_namespace.c:476 net/core/net_namespace.c:467) cleanup_net (net/core/net_namespace.c:664 (discriminator 3)) process_one_work (kernel/workqueue.c:3229) worker_thread (kernel/workqueue.c:3304 kernel/workqueue.c:3391 ---truncated---
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 459aa660eb1d8ce67080da1983bb81d716aa5a69 , < c986380c1d5274c4d5e935addc807d6791cc23eb (git)
    Affected: 459aa660eb1d8ce67080da1983bb81d716aa5a69 , < 5f1678346109ff3a6d229d33437fcba3cce9209d (git)
    Affected: 459aa660eb1d8ce67080da1983bb81d716aa5a69 , < 036f8d814a2cd11ee8ef62b8f3e7ce5dec0ee4f3 (git)
    Affected: 459aa660eb1d8ce67080da1983bb81d716aa5a69 , < efec287cbac92ac6ee8312a89221854760e13b34 (git)
    Affected: 459aa660eb1d8ce67080da1983bb81d716aa5a69 , < bb11f992f5a475bc68ef959f17a55306f0328495 (git)
    Affected: 459aa660eb1d8ce67080da1983bb81d716aa5a69 , < 86f73d4ab2f27deeff22ba9336ad103d94f12ac7 (git)
    Affected: 459aa660eb1d8ce67080da1983bb81d716aa5a69 , < eb28fd76c0a08a47b470677c6cef9dd1c60e92d1 (git)
    Create a notification for this product.
    Linux Linux Affected: 4.7
    Unaffected: 0 , < 4.7 (semver)
    Unaffected: 5.4.290 , ≤ 5.4.* (semver)
    Unaffected: 5.10.234 , ≤ 5.10.* (semver)
    Unaffected: 5.15.177 , ≤ 5.15.* (semver)
    Unaffected: 6.1.127 , ≤ 6.1.* (semver)
    Unaffected: 6.6.74 , ≤ 6.6.* (semver)
    Unaffected: 6.12.11 , ≤ 6.12.* (semver)
    Unaffected: 6.13 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:58:55.888Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:03:10.577Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "drivers/net/gtp.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "c986380c1d5274c4d5e935addc807d6791cc23eb",
                  "status": "affected",
                  "version": "459aa660eb1d8ce67080da1983bb81d716aa5a69",
                  "versionType": "git"
                },
                {
                  "lessThan": "5f1678346109ff3a6d229d33437fcba3cce9209d",
                  "status": "affected",
                  "version": "459aa660eb1d8ce67080da1983bb81d716aa5a69",
                  "versionType": "git"
                },
                {
                  "lessThan": "036f8d814a2cd11ee8ef62b8f3e7ce5dec0ee4f3",
                  "status": "affected",
                  "version": "459aa660eb1d8ce67080da1983bb81d716aa5a69",
                  "versionType": "git"
                },
                {
                  "lessThan": "efec287cbac92ac6ee8312a89221854760e13b34",
                  "status": "affected",
                  "version": "459aa660eb1d8ce67080da1983bb81d716aa5a69",
                  "versionType": "git"
                },
                {
                  "lessThan": "bb11f992f5a475bc68ef959f17a55306f0328495",
                  "status": "affected",
                  "version": "459aa660eb1d8ce67080da1983bb81d716aa5a69",
                  "versionType": "git"
                },
                {
                  "lessThan": "86f73d4ab2f27deeff22ba9336ad103d94f12ac7",
                  "status": "affected",
                  "version": "459aa660eb1d8ce67080da1983bb81d716aa5a69",
                  "versionType": "git"
                },
                {
                  "lessThan": "eb28fd76c0a08a47b470677c6cef9dd1c60e92d1",
                  "status": "affected",
                  "version": "459aa660eb1d8ce67080da1983bb81d716aa5a69",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "drivers/net/gtp.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.7"
                },
                {
                  "lessThan": "4.7",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.290",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.234",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.177",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.127",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.74",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.11",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.13",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.290",
                      "versionStartIncluding": "4.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.234",
                      "versionStartIncluding": "4.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.177",
                      "versionStartIncluding": "4.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.127",
                      "versionStartIncluding": "4.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.74",
                      "versionStartIncluding": "4.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.11",
                      "versionStartIncluding": "4.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13",
                      "versionStartIncluding": "4.7",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ngtp: Destroy device along with udp socket\u0027s netns dismantle.\n\ngtp_newlink() links the device to a list in dev_net(dev) instead of\nsrc_net, where a udp tunnel socket is created.\n\nEven when src_net is removed, the device stays alive on dev_net(dev).\nThen, removing src_net triggers the splat below. [0]\n\nIn this example, gtp0 is created in ns2, and the udp socket is created\nin ns1.\n\n  ip netns add ns1\n  ip netns add ns2\n  ip -n ns1 link add netns ns2 name gtp0 type gtp role sgsn\n  ip netns del ns1\n\nLet\u0027s link the device to the socket\u0027s netns instead.\n\nNow, gtp_net_exit_batch_rtnl() needs another netdev iteration to remove\nall gtp devices in the netns.\n\n[0]:\nref_tracker: net notrefcnt@000000003d6e7d05 has 1/2 users at\n     sk_alloc (./include/net/net_namespace.h:345 net/core/sock.c:2236)\n     inet_create (net/ipv4/af_inet.c:326 net/ipv4/af_inet.c:252)\n     __sock_create (net/socket.c:1558)\n     udp_sock_create4 (net/ipv4/udp_tunnel_core.c:18)\n     gtp_create_sock (./include/net/udp_tunnel.h:59 drivers/net/gtp.c:1423)\n     gtp_create_sockets (drivers/net/gtp.c:1447)\n     gtp_newlink (drivers/net/gtp.c:1507)\n     rtnl_newlink (net/core/rtnetlink.c:3786 net/core/rtnetlink.c:3897 net/core/rtnetlink.c:4012)\n     rtnetlink_rcv_msg (net/core/rtnetlink.c:6922)\n     netlink_rcv_skb (net/netlink/af_netlink.c:2542)\n     netlink_unicast (net/netlink/af_netlink.c:1321 net/netlink/af_netlink.c:1347)\n     netlink_sendmsg (net/netlink/af_netlink.c:1891)\n     ____sys_sendmsg (net/socket.c:711 net/socket.c:726 net/socket.c:2583)\n     ___sys_sendmsg (net/socket.c:2639)\n     __sys_sendmsg (net/socket.c:2669)\n     do_syscall_64 (arch/x86/entry/common.c:52 arch/x86/entry/common.c:83)\n\nWARNING: CPU: 1 PID: 60 at lib/ref_tracker.c:179 ref_tracker_dir_exit (lib/ref_tracker.c:179)\nModules linked in:\nCPU: 1 UID: 0 PID: 60 Comm: kworker/u16:2 Not tainted 6.13.0-rc5-00147-g4c1224501e9d #5\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014\nWorkqueue: netns cleanup_net\nRIP: 0010:ref_tracker_dir_exit (lib/ref_tracker.c:179)\nCode: 00 00 00 fc ff df 4d 8b 26 49 bd 00 01 00 00 00 00 ad de 4c 39 f5 0f 85 df 00 00 00 48 8b 74 24 08 48 89 df e8 a5 cc 12 02 90 \u003c0f\u003e 0b 90 48 8d 6b 44 be 04 00 00 00 48 89 ef e8 80 de 67 ff 48 89\nRSP: 0018:ff11000009a07b60 EFLAGS: 00010286\nRAX: 0000000000002bd3 RBX: ff1100000f4e1aa0 RCX: 1ffffffff0e40ac6\nRDX: 0000000000000000 RSI: 0000000000000000 RDI: ffffffff8423ee3c\nRBP: ff1100000f4e1af0 R08: 0000000000000001 R09: fffffbfff0e395ae\nR10: 0000000000000001 R11: 0000000000036001 R12: ff1100000f4e1af0\nR13: dead000000000100 R14: ff1100000f4e1af0 R15: dffffc0000000000\nFS:  0000000000000000(0000) GS:ff1100006ce80000(0000) knlGS:0000000000000000\nCS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f9b2464bd98 CR3: 0000000005286005 CR4: 0000000000771ef0\nDR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\nDR3: 0000000000000000 DR6: 00000000fffe07f0 DR7: 0000000000000400\nPKRU: 55555554\nCall Trace:\n \u003cTASK\u003e\n ? __warn (kernel/panic.c:748)\n ? ref_tracker_dir_exit (lib/ref_tracker.c:179)\n ? report_bug (lib/bug.c:201 lib/bug.c:219)\n ? handle_bug (arch/x86/kernel/traps.c:285)\n ? exc_invalid_op (arch/x86/kernel/traps.c:309 (discriminator 1))\n ? asm_exc_invalid_op (./arch/x86/include/asm/idtentry.h:621)\n ? _raw_spin_unlock_irqrestore (./arch/x86/include/asm/irqflags.h:42 ./arch/x86/include/asm/irqflags.h:97 ./arch/x86/include/asm/irqflags.h:155 ./include/linux/spinlock_api_smp.h:151 kernel/locking/spinlock.c:194)\n ? ref_tracker_dir_exit (lib/ref_tracker.c:179)\n ? __pfx_ref_tracker_dir_exit (lib/ref_tracker.c:158)\n ? kfree (mm/slub.c:4613 mm/slub.c:4761)\n net_free (net/core/net_namespace.c:476 net/core/net_namespace.c:467)\n cleanup_net (net/core/net_namespace.c:664 (discriminator 3))\n process_one_work (kernel/workqueue.c:3229)\n worker_thread (kernel/workqueue.c:3304 kernel/workqueue.c:3391\n---truncated---"
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - The vulnerability is triggered entirely through local syscalls \u2014 an RTM_NEWLINK netlink message creating a GTP device with the link in a different netns than the netlink socket, followed by teardown of that netns. No remote packet processing is involved in reaching the bug.\nAC:L - The four-command reproducer in the commit message triggers it deterministically with no race and no dependence on uncontrolled memory layout; reoccupying the freed struct net is done by simply calling unshare(CLONE_NEWNET), which is fully under attacker control.\nPR:L - Both gates on the path (netlink_net_capable and rtnl_link_get_net_capable) check CAP_NET_ADMIN against net-\u003euser_ns, which an unprivileged user obtains for netns it creates via `unshare -Urn`; the gtp module is autoloaded on demand from the same path.\nUI:N - The attacker performs every step \u2014 creating the namespaces, creating the GTP link, and destroying the socket\u0027s namespace \u2014 with no action required from any other user.\nS:U - The dangling struct net pointer and the resulting corruption are confined to the kernel\u0027s own security authority; there is no hypervisor, IOMMU, or other authority boundary crossed.\nC:H - This is a use-after-free of struct net whose freed slab object the attacker can deterministically reoccupy, so subsequent reads through gtp-\u003enet and sock_net(sk) return attacker-groomed contents and route/socket lookups are performed against a foreign namespace\u0027s tables, enabling information disclosure.\nI:H - The teardown path performs __netns_tracker_free() on the freed net \u2014 a spinlock acquisition and list_del() into freed memory \u2014 giving a write-after-free/unlink primitive, and the aliased netns allows packets to be routed and sockets to be hashed into a namespace the attacker does not own.\nA:H - The bug reliably produces a ref_tracker_dir_exit() WARNING splat in cleanup_net (a panic under panic_on_warn), and the subsequent use-after-free of struct net causes kernel oopses/panics on device teardown or transmit."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:53:34.427Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/c986380c1d5274c4d5e935addc807d6791cc23eb"
            },
            {
              "url": "https://git.kernel.org/stable/c/5f1678346109ff3a6d229d33437fcba3cce9209d"
            },
            {
              "url": "https://git.kernel.org/stable/c/036f8d814a2cd11ee8ef62b8f3e7ce5dec0ee4f3"
            },
            {
              "url": "https://git.kernel.org/stable/c/efec287cbac92ac6ee8312a89221854760e13b34"
            },
            {
              "url": "https://git.kernel.org/stable/c/bb11f992f5a475bc68ef959f17a55306f0328495"
            },
            {
              "url": "https://git.kernel.org/stable/c/86f73d4ab2f27deeff22ba9336ad103d94f12ac7"
            },
            {
              "url": "https://git.kernel.org/stable/c/eb28fd76c0a08a47b470677c6cef9dd1c60e92d1"
            }
          ],
          "title": "gtp: Destroy device along with udp socket\u0027s netns dismantle.",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2025-21678",
        "datePublished": "2025-01-31T11:25:39.500Z",
        "dateReserved": "2024-12-29T08:45:45.738Z",
        "dateUpdated": "2026-08-05T11:53:34.427Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-57940 (GCVE-0-2024-57940)

    Vulnerability from cvelistv5 – Published: 2025-01-21 12:18 – Updated: 2026-05-12 12:01
    VLAI
    Title
    exfat: fix the infinite loop in exfat_readdir()
    Summary
    In the Linux kernel, the following vulnerability has been resolved: exfat: fix the infinite loop in exfat_readdir() If the file system is corrupted so that a cluster is linked to itself in the cluster chain, and there is an unused directory entry in the cluster, 'dentry' will not be incremented, causing condition 'dentry < max_dentries' unable to prevent an infinite loop. This infinite loop causes s_lock not to be released, and other tasks will hang, such as exfat_sync_fs(). This commit stops traversing the cluster chain when there is unused directory entry in the cluster to avoid this infinite loop.
    Severity
    No CVSS data available.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: ca06197382bde0a3bc20215595d1c9ce20c6e341 , < d8cfbb8723bd3d3222f360227a1cc15227189ca6 (git)
    Affected: ca06197382bde0a3bc20215595d1c9ce20c6e341 , < 28c21f0ac5293a4bf19b3e0e32005d6dd31a6c17 (git)
    Affected: ca06197382bde0a3bc20215595d1c9ce20c6e341 , < 31beabd0f47f8c3ed9965ba861c9e5b252d4920a (git)
    Affected: ca06197382bde0a3bc20215595d1c9ce20c6e341 , < dc1d7afceb982e8f666e70a582e6b5aa806de063 (git)
    Affected: ca06197382bde0a3bc20215595d1c9ce20c6e341 , < d9ea94f5cd117d56e573696d0045ab3044185a15 (git)
    Affected: ca06197382bde0a3bc20215595d1c9ce20c6e341 , < fee873761bd978d077d8c55334b4966ac4cb7b59 (git)
    Create a notification for this product.
    Linux Linux Affected: 5.7
    Unaffected: 0 , < 5.7 (semver)
    Unaffected: 5.10.234 , ≤ 5.10.* (semver)
    Unaffected: 5.15.177 , ≤ 5.15.* (semver)
    Unaffected: 6.1.125 , ≤ 6.1.* (semver)
    Unaffected: 6.6.72 , ≤ 6.6.* (semver)
    Unaffected: 6.12.10 , ≤ 6.12.* (semver)
    Unaffected: 6.13 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:56:09.764Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:01:40.296Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "fs/exfat/dir.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "d8cfbb8723bd3d3222f360227a1cc15227189ca6",
                  "status": "affected",
                  "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                  "versionType": "git"
                },
                {
                  "lessThan": "28c21f0ac5293a4bf19b3e0e32005d6dd31a6c17",
                  "status": "affected",
                  "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                  "versionType": "git"
                },
                {
                  "lessThan": "31beabd0f47f8c3ed9965ba861c9e5b252d4920a",
                  "status": "affected",
                  "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                  "versionType": "git"
                },
                {
                  "lessThan": "dc1d7afceb982e8f666e70a582e6b5aa806de063",
                  "status": "affected",
                  "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                  "versionType": "git"
                },
                {
                  "lessThan": "d9ea94f5cd117d56e573696d0045ab3044185a15",
                  "status": "affected",
                  "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                  "versionType": "git"
                },
                {
                  "lessThan": "fee873761bd978d077d8c55334b4966ac4cb7b59",
                  "status": "affected",
                  "version": "ca06197382bde0a3bc20215595d1c9ce20c6e341",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "fs/exfat/dir.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "5.7"
                },
                {
                  "lessThan": "5.7",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.234",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.177",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.125",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.72",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.13",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.234",
                      "versionStartIncluding": "5.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.177",
                      "versionStartIncluding": "5.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.125",
                      "versionStartIncluding": "5.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.72",
                      "versionStartIncluding": "5.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.10",
                      "versionStartIncluding": "5.7",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13",
                      "versionStartIncluding": "5.7",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nexfat: fix the infinite loop in exfat_readdir()\n\nIf the file system is corrupted so that a cluster is linked to\nitself in the cluster chain, and there is an unused directory\nentry in the cluster, \u0027dentry\u0027 will not be incremented, causing\ncondition \u0027dentry \u003c max_dentries\u0027 unable to prevent an infinite\nloop.\n\nThis infinite loop causes s_lock not to be released, and other\ntasks will hang, such as exfat_sync_fs().\n\nThis commit stops traversing the cluster chain when there is unused\ndirectory entry in the cluster to avoid this infinite loop."
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T21:01:04.019Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/d8cfbb8723bd3d3222f360227a1cc15227189ca6"
            },
            {
              "url": "https://git.kernel.org/stable/c/28c21f0ac5293a4bf19b3e0e32005d6dd31a6c17"
            },
            {
              "url": "https://git.kernel.org/stable/c/31beabd0f47f8c3ed9965ba861c9e5b252d4920a"
            },
            {
              "url": "https://git.kernel.org/stable/c/dc1d7afceb982e8f666e70a582e6b5aa806de063"
            },
            {
              "url": "https://git.kernel.org/stable/c/d9ea94f5cd117d56e573696d0045ab3044185a15"
            },
            {
              "url": "https://git.kernel.org/stable/c/fee873761bd978d077d8c55334b4966ac4cb7b59"
            }
          ],
          "title": "exfat: fix the infinite loop in exfat_readdir()",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-57940",
        "datePublished": "2025-01-21T12:18:09.150Z",
        "dateReserved": "2025-01-19T11:50:08.378Z",
        "dateUpdated": "2026-05-12T12:01:40.296Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-21653 (GCVE-0-2025-21653)

    Vulnerability from cvelistv5 – Published: 2025-01-19 10:18 – Updated: 2026-05-12 12:03
    VLAI
    Title
    net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute
    Summary
    In the Linux kernel, the following vulnerability has been resolved: net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute syzbot found that TCA_FLOW_RSHIFT attribute was not validated. Right shitfing a 32bit integer is undefined for large shift values. UBSAN: shift-out-of-bounds in net/sched/cls_flow.c:329:23 shift exponent 9445 is too large for 32-bit type 'u32' (aka 'unsigned int') CPU: 1 UID: 0 PID: 54 Comm: kworker/u8:3 Not tainted 6.13.0-rc3-syzkaller-00180-g4f619d518db9 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 Workqueue: ipv6_addrconf addrconf_dad_work Call Trace: <TASK> __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120 ubsan_epilogue lib/ubsan.c:231 [inline] __ubsan_handle_shift_out_of_bounds+0x3c8/0x420 lib/ubsan.c:468 flow_classify+0x24d5/0x25b0 net/sched/cls_flow.c:329 tc_classify include/net/tc_wrapper.h:197 [inline] __tcf_classify net/sched/cls_api.c:1771 [inline] tcf_classify+0x420/0x1160 net/sched/cls_api.c:1867 sfb_classify net/sched/sch_sfb.c:260 [inline] sfb_enqueue+0x3ad/0x18b0 net/sched/sch_sfb.c:318 dev_qdisc_enqueue+0x4b/0x290 net/core/dev.c:3793 __dev_xmit_skb net/core/dev.c:3889 [inline] __dev_queue_xmit+0xf0e/0x3f50 net/core/dev.c:4400 dev_queue_xmit include/linux/netdevice.h:3168 [inline] neigh_hh_output include/net/neighbour.h:523 [inline] neigh_output include/net/neighbour.h:537 [inline] ip_finish_output2+0xd41/0x1390 net/ipv4/ip_output.c:236 iptunnel_xmit+0x55d/0x9b0 net/ipv4/ip_tunnel_core.c:82 udp_tunnel_xmit_skb+0x262/0x3b0 net/ipv4/udp_tunnel_core.c:173 geneve_xmit_skb drivers/net/geneve.c:916 [inline] geneve_xmit+0x21dc/0x2d00 drivers/net/geneve.c:1039 __netdev_start_xmit include/linux/netdevice.h:5002 [inline] netdev_start_xmit include/linux/netdevice.h:5011 [inline] xmit_one net/core/dev.c:3590 [inline] dev_hard_start_xmit+0x27a/0x7d0 net/core/dev.c:3606 __dev_queue_xmit+0x1b73/0x3f50 net/core/dev.c:4434
    Severity
    No CVSS data available.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: e5dfb815181fcb186d6080ac3a091eadff2d98fe , < 9858f4afeb2e59506e714176bd3e135539a3eeec (git)
    Affected: e5dfb815181fcb186d6080ac3a091eadff2d98fe , < 43658e4a5f2770ad94e93362885ff51c10cf3179 (git)
    Affected: e5dfb815181fcb186d6080ac3a091eadff2d98fe , < a313d6e6d5f3a631cae5a241c392c28868aa5c5e (git)
    Affected: e5dfb815181fcb186d6080ac3a091eadff2d98fe , < 2011749ca96460386844dfc7e0fde53ebee96f3c (git)
    Affected: e5dfb815181fcb186d6080ac3a091eadff2d98fe , < e54beb9aed2a90dddf4c5d68fcfc9a01f3e40a61 (git)
    Affected: e5dfb815181fcb186d6080ac3a091eadff2d98fe , < 6fde663f7321418996645ee602a473457640542f (git)
    Affected: e5dfb815181fcb186d6080ac3a091eadff2d98fe , < a039e54397c6a75b713b9ce7894a62e06956aa92 (git)
    Create a notification for this product.
    Linux Linux Affected: 2.6.25
    Unaffected: 0 , < 2.6.25 (semver)
    Unaffected: 5.4.290 , ≤ 5.4.* (semver)
    Unaffected: 5.10.234 , ≤ 5.10.* (semver)
    Unaffected: 5.15.177 , ≤ 5.15.* (semver)
    Unaffected: 6.1.125 , ≤ 6.1.* (semver)
    Unaffected: 6.6.72 , ≤ 6.6.* (semver)
    Unaffected: 6.12.10 , ≤ 6.12.* (semver)
    Unaffected: 6.13 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:58:33.343Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:03:05.797Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/sched/cls_flow.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "9858f4afeb2e59506e714176bd3e135539a3eeec",
                  "status": "affected",
                  "version": "e5dfb815181fcb186d6080ac3a091eadff2d98fe",
                  "versionType": "git"
                },
                {
                  "lessThan": "43658e4a5f2770ad94e93362885ff51c10cf3179",
                  "status": "affected",
                  "version": "e5dfb815181fcb186d6080ac3a091eadff2d98fe",
                  "versionType": "git"
                },
                {
                  "lessThan": "a313d6e6d5f3a631cae5a241c392c28868aa5c5e",
                  "status": "affected",
                  "version": "e5dfb815181fcb186d6080ac3a091eadff2d98fe",
                  "versionType": "git"
                },
                {
                  "lessThan": "2011749ca96460386844dfc7e0fde53ebee96f3c",
                  "status": "affected",
                  "version": "e5dfb815181fcb186d6080ac3a091eadff2d98fe",
                  "versionType": "git"
                },
                {
                  "lessThan": "e54beb9aed2a90dddf4c5d68fcfc9a01f3e40a61",
                  "status": "affected",
                  "version": "e5dfb815181fcb186d6080ac3a091eadff2d98fe",
                  "versionType": "git"
                },
                {
                  "lessThan": "6fde663f7321418996645ee602a473457640542f",
                  "status": "affected",
                  "version": "e5dfb815181fcb186d6080ac3a091eadff2d98fe",
                  "versionType": "git"
                },
                {
                  "lessThan": "a039e54397c6a75b713b9ce7894a62e06956aa92",
                  "status": "affected",
                  "version": "e5dfb815181fcb186d6080ac3a091eadff2d98fe",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/sched/cls_flow.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.6.25"
                },
                {
                  "lessThan": "2.6.25",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.290",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.234",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.177",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.125",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.72",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.13",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.290",
                      "versionStartIncluding": "2.6.25",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.234",
                      "versionStartIncluding": "2.6.25",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.177",
                      "versionStartIncluding": "2.6.25",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.125",
                      "versionStartIncluding": "2.6.25",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.72",
                      "versionStartIncluding": "2.6.25",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.10",
                      "versionStartIncluding": "2.6.25",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13",
                      "versionStartIncluding": "2.6.25",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute\n\nsyzbot found that TCA_FLOW_RSHIFT attribute was not validated.\nRight shitfing a 32bit integer is undefined for large shift values.\n\nUBSAN: shift-out-of-bounds in net/sched/cls_flow.c:329:23\nshift exponent 9445 is too large for 32-bit type \u0027u32\u0027 (aka \u0027unsigned int\u0027)\nCPU: 1 UID: 0 PID: 54 Comm: kworker/u8:3 Not tainted 6.13.0-rc3-syzkaller-00180-g4f619d518db9 #0\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024\nWorkqueue: ipv6_addrconf addrconf_dad_work\nCall Trace:\n \u003cTASK\u003e\n  __dump_stack lib/dump_stack.c:94 [inline]\n  dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120\n  ubsan_epilogue lib/ubsan.c:231 [inline]\n  __ubsan_handle_shift_out_of_bounds+0x3c8/0x420 lib/ubsan.c:468\n  flow_classify+0x24d5/0x25b0 net/sched/cls_flow.c:329\n  tc_classify include/net/tc_wrapper.h:197 [inline]\n  __tcf_classify net/sched/cls_api.c:1771 [inline]\n  tcf_classify+0x420/0x1160 net/sched/cls_api.c:1867\n  sfb_classify net/sched/sch_sfb.c:260 [inline]\n  sfb_enqueue+0x3ad/0x18b0 net/sched/sch_sfb.c:318\n  dev_qdisc_enqueue+0x4b/0x290 net/core/dev.c:3793\n  __dev_xmit_skb net/core/dev.c:3889 [inline]\n  __dev_queue_xmit+0xf0e/0x3f50 net/core/dev.c:4400\n  dev_queue_xmit include/linux/netdevice.h:3168 [inline]\n  neigh_hh_output include/net/neighbour.h:523 [inline]\n  neigh_output include/net/neighbour.h:537 [inline]\n  ip_finish_output2+0xd41/0x1390 net/ipv4/ip_output.c:236\n  iptunnel_xmit+0x55d/0x9b0 net/ipv4/ip_tunnel_core.c:82\n  udp_tunnel_xmit_skb+0x262/0x3b0 net/ipv4/udp_tunnel_core.c:173\n  geneve_xmit_skb drivers/net/geneve.c:916 [inline]\n  geneve_xmit+0x21dc/0x2d00 drivers/net/geneve.c:1039\n  __netdev_start_xmit include/linux/netdevice.h:5002 [inline]\n  netdev_start_xmit include/linux/netdevice.h:5011 [inline]\n  xmit_one net/core/dev.c:3590 [inline]\n  dev_hard_start_xmit+0x27a/0x7d0 net/core/dev.c:3606\n  __dev_queue_xmit+0x1b73/0x3f50 net/core/dev.c:4434"
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T21:03:50.397Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/9858f4afeb2e59506e714176bd3e135539a3eeec"
            },
            {
              "url": "https://git.kernel.org/stable/c/43658e4a5f2770ad94e93362885ff51c10cf3179"
            },
            {
              "url": "https://git.kernel.org/stable/c/a313d6e6d5f3a631cae5a241c392c28868aa5c5e"
            },
            {
              "url": "https://git.kernel.org/stable/c/2011749ca96460386844dfc7e0fde53ebee96f3c"
            },
            {
              "url": "https://git.kernel.org/stable/c/e54beb9aed2a90dddf4c5d68fcfc9a01f3e40a61"
            },
            {
              "url": "https://git.kernel.org/stable/c/6fde663f7321418996645ee602a473457640542f"
            },
            {
              "url": "https://git.kernel.org/stable/c/a039e54397c6a75b713b9ce7894a62e06956aa92"
            }
          ],
          "title": "net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2025-21653",
        "datePublished": "2025-01-19T10:18:10.354Z",
        "dateReserved": "2024-12-29T08:45:45.729Z",
        "dateUpdated": "2026-05-12T12:03:05.797Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-21647 (GCVE-0-2025-21647)

    Vulnerability from cvelistv5 – Published: 2025-01-19 10:18 – Updated: 2026-08-05 11:53
    VLAI
    Title
    sched: sch_cake: add bounds checks to host bulk flow fairness counts
    Summary
    In the Linux kernel, the following vulnerability has been resolved: sched: sch_cake: add bounds checks to host bulk flow fairness counts Even though we fixed a logic error in the commit cited below, syzbot still managed to trigger an underflow of the per-host bulk flow counters, leading to an out of bounds memory access. To avoid any such logic errors causing out of bounds memory accesses, this commit factors out all accesses to the per-host bulk flow counters to a series of helpers that perform bounds-checking before any increments and decrements. This also has the benefit of improving readability by moving the conditional checks for the flow mode into these helpers, instead of having them spread out throughout the code (which was the cause of the original logic error). As part of this change, the flow quantum calculation is consolidated into a helper function, which means that the dithering applied to the ost load scaling is now applied both in the DRR rotation and when a sparse flow's quantum is first initiated. The only user-visible effect of this is that the maximum packet size that can be sent while a flow stays sparse will now vary with +/- one byte in some cases. This should not make a noticeable difference in practice, and thus it's not worth complicating the code to preserve the old behaviour.
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 4a4eeefa514db570be025ab46d779af180e2c9bb , < 44fe1efb4961c1a5ccab16bb579dfc6b308ad58b (git)
    Affected: 7725152b54d295b7da5e34c2f419539b30d017bd , < b1a1743aaa4906c41c426eda97e2e2586f79246d (git)
    Affected: cde71a5677971f4f1b69b25e854891dbe78066a4 , < bb0245fa72b783cb23a9949c5048781341e91423 (git)
    Affected: 549e407569e08459d16122341d332cb508024094 , < a777e06dfc72bed73c05dcb437d7c27ad5f90f3f (git)
    Affected: d4a9039a7b3d8005b90c7b1a55a306444f0e5447 , < 27202e2e8721c3b23831563c36ed5ac7818641ba (git)
    Affected: 546ea84d07e3e324644025e2aae2d12ea4c5896e , < 91bb18950b88f955838ec0c1d97f74d135756dc7 (git)
    Affected: 546ea84d07e3e324644025e2aae2d12ea4c5896e , < 737d4d91d35b5f7fa5bb442651472277318b0bfd (git)
    Affected: d7c01c0714c04431b5e18cf17a9ea68a553d1c3c (git)
    Affected: 5.4.284 , < 5.4.291 (semver)
    Affected: 5.10.226 , < 5.10.235 (semver)
    Affected: 5.15.167 , < 5.15.179 (semver)
    Affected: 6.1.110 , < 6.1.125 (semver)
    Affected: 6.6.51 , < 6.6.72 (semver)
    Affected: 6.10.10 , < 6.11 (semver)
    Create a notification for this product.
    Linux Linux Affected: 6.11
    Unaffected: 0 , < 6.11 (semver)
    Unaffected: 5.4.291 , ≤ 5.4.* (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.125 , ≤ 6.1.* (semver)
    Unaffected: 6.6.72 , ≤ 6.6.* (semver)
    Unaffected: 6.12.10 , ≤ 6.12.* (semver)
    Unaffected: 6.13 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:58:27.786Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T12:03:03.268Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/sched/sch_cake.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "44fe1efb4961c1a5ccab16bb579dfc6b308ad58b",
                  "status": "affected",
                  "version": "4a4eeefa514db570be025ab46d779af180e2c9bb",
                  "versionType": "git"
                },
                {
                  "lessThan": "b1a1743aaa4906c41c426eda97e2e2586f79246d",
                  "status": "affected",
                  "version": "7725152b54d295b7da5e34c2f419539b30d017bd",
                  "versionType": "git"
                },
                {
                  "lessThan": "bb0245fa72b783cb23a9949c5048781341e91423",
                  "status": "affected",
                  "version": "cde71a5677971f4f1b69b25e854891dbe78066a4",
                  "versionType": "git"
                },
                {
                  "lessThan": "a777e06dfc72bed73c05dcb437d7c27ad5f90f3f",
                  "status": "affected",
                  "version": "549e407569e08459d16122341d332cb508024094",
                  "versionType": "git"
                },
                {
                  "lessThan": "27202e2e8721c3b23831563c36ed5ac7818641ba",
                  "status": "affected",
                  "version": "d4a9039a7b3d8005b90c7b1a55a306444f0e5447",
                  "versionType": "git"
                },
                {
                  "lessThan": "91bb18950b88f955838ec0c1d97f74d135756dc7",
                  "status": "affected",
                  "version": "546ea84d07e3e324644025e2aae2d12ea4c5896e",
                  "versionType": "git"
                },
                {
                  "lessThan": "737d4d91d35b5f7fa5bb442651472277318b0bfd",
                  "status": "affected",
                  "version": "546ea84d07e3e324644025e2aae2d12ea4c5896e",
                  "versionType": "git"
                },
                {
                  "status": "affected",
                  "version": "d7c01c0714c04431b5e18cf17a9ea68a553d1c3c",
                  "versionType": "git"
                },
                {
                  "lessThan": "5.4.291",
                  "status": "affected",
                  "version": "5.4.284",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.10.235",
                  "status": "affected",
                  "version": "5.10.226",
                  "versionType": "semver"
                },
                {
                  "lessThan": "5.15.179",
                  "status": "affected",
                  "version": "5.15.167",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.1.125",
                  "status": "affected",
                  "version": "6.1.110",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.6.72",
                  "status": "affected",
                  "version": "6.6.51",
                  "versionType": "semver"
                },
                {
                  "lessThan": "6.11",
                  "status": "affected",
                  "version": "6.10.10",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/sched/sch_cake.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "6.11"
                },
                {
                  "lessThan": "6.11",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.291",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.125",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.72",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.12.*",
                  "status": "unaffected",
                  "version": "6.12.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.13",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.291",
                      "versionStartIncluding": "5.4.284",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "5.10.226",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "5.15.167",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.125",
                      "versionStartIncluding": "6.1.110",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.72",
                      "versionStartIncluding": "6.6.51",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12.10",
                      "versionStartIncluding": "6.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.13",
                      "versionStartIncluding": "6.11",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionStartIncluding": "6.10.10",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nsched: sch_cake: add bounds checks to host bulk flow fairness counts\n\nEven though we fixed a logic error in the commit cited below, syzbot\nstill managed to trigger an underflow of the per-host bulk flow\ncounters, leading to an out of bounds memory access.\n\nTo avoid any such logic errors causing out of bounds memory accesses,\nthis commit factors out all accesses to the per-host bulk flow counters\nto a series of helpers that perform bounds-checking before any\nincrements and decrements. This also has the benefit of improving\nreadability by moving the conditional checks for the flow mode into\nthese helpers, instead of having them spread out throughout the\ncode (which was the cause of the original logic error).\n\nAs part of this change, the flow quantum calculation is consolidated\ninto a helper function, which means that the dithering applied to the\nost load scaling is now applied both in the DRR rotation and when a\nsparse flow\u0027s quantum is first initiated. The only user-visible effect\nof this is that the maximum packet size that can be sent while a flow\nstays sparse will now vary with +/- one byte in some cases. This should\nnot make a noticeable difference in practice, and thus it\u0027s not worth\ncomplicating the code to preserve the old behaviour."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:L - Reaching the bug requires attaching the cake qdisc via rtnetlink (`tc qdisc add ... cake`) and then driving packets through it, which is a local netlink/syscall operation. Although cake also processes remotely-originated traffic on routers, the reliable and primary attack path is local, consistent with tc/qdisc classification.\nAC:L - The vulnerable host-fairness accounting is active in cake\u0027s default `triple-isolate` flow mode, and the attacker fully controls the packet 5-tuples used for the set-associative hash, so filling an 8-way set and forcing the mis-targeted decrement is deterministic and repeatable.\nPR:L - Qdisc installation is gated by `netlink_net_capable(skb, CAP_NET_ADMIN)`, which is evaluated against the netns user namespace, so any unprivileged user can obtain it with `unshare -Urn` and then attach cake to a loopback/veth device.\nUI:N - The attacker performs the qdisc setup and generates the triggering traffic entirely on their own; no action by any other user or administrator is needed.\nS:U - The out-of-bounds read and the counter corruption are confined to kernel memory within the same security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The u16 underflow makes `quantum_div[host_load]` read up to ~128 KB beyond a 1025-entry static array, and the value is folded into `flow-\u003edeficit`, which is exported via `TCA_CAKE_STATS_DEFICIT` \u2014 repeated samples defeat the random dithering and recover out-of-bounds kernel data, with the index steerable by additional spurious decrements.\nI:L - The bug persistently corrupts the per-host bulk-flow counters and injects out-of-bounds data into the scheduler\u0027s deficit state, modifying kernel data the attacker should not be able to touch, but there is no out-of-bounds write and no control over the written values.\nA:H - The wild index trips `WARN_ON(host_load \u003e CAKE_QUEUES)` (a panic under `panic_on_warn`) and reads far past the module\u0027s `.bss` into potentially unmapped vmalloc space, causing an oops; the qdisc state stays corrupted so the condition recurs on every dequeue."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:53:21.504Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/44fe1efb4961c1a5ccab16bb579dfc6b308ad58b"
            },
            {
              "url": "https://git.kernel.org/stable/c/b1a1743aaa4906c41c426eda97e2e2586f79246d"
            },
            {
              "url": "https://git.kernel.org/stable/c/bb0245fa72b783cb23a9949c5048781341e91423"
            },
            {
              "url": "https://git.kernel.org/stable/c/a777e06dfc72bed73c05dcb437d7c27ad5f90f3f"
            },
            {
              "url": "https://git.kernel.org/stable/c/27202e2e8721c3b23831563c36ed5ac7818641ba"
            },
            {
              "url": "https://git.kernel.org/stable/c/91bb18950b88f955838ec0c1d97f74d135756dc7"
            },
            {
              "url": "https://git.kernel.org/stable/c/737d4d91d35b5f7fa5bb442651472277318b0bfd"
            }
          ],
          "title": "sched: sch_cake: add bounds checks to host bulk flow fairness counts",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2025-21647",
        "datePublished": "2025-01-19T10:18:04.415Z",
        "dateReserved": "2024-12-29T08:45:45.728Z",
        "dateUpdated": "2026-08-05T11:53:21.504Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-53124 (GCVE-0-2024-53124)

    Vulnerability from cvelistv5 – Published: 2024-12-02 13:44 – Updated: 2026-09-08 08:39
    VLAI
    Title
    net: fix data-races around sk->sk_forward_alloc
    Summary
    In the Linux kernel, the following vulnerability has been resolved: net: fix data-races around sk->sk_forward_alloc Syzkaller reported this warning: ------------[ cut here ]------------ WARNING: CPU: 0 PID: 16 at net/ipv4/af_inet.c:156 inet_sock_destruct+0x1c5/0x1e0 Modules linked in: CPU: 0 UID: 0 PID: 16 Comm: ksoftirqd/0 Not tainted 6.12.0-rc5 #26 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 RIP: 0010:inet_sock_destruct+0x1c5/0x1e0 Code: 24 12 4c 89 e2 5b 48 c7 c7 98 ec bb 82 41 5c e9 d1 18 17 ff 4c 89 e6 5b 48 c7 c7 d0 ec bb 82 41 5c e9 bf 18 17 ff 0f 0b eb 83 <0f> 0b eb 97 0f 0b eb 87 0f 0b e9 68 ff ff ff 66 66 2e 0f 1f 84 00 RSP: 0018:ffffc9000008bd90 EFLAGS: 00010206 RAX: 0000000000000300 RBX: ffff88810b172a90 RCX: 0000000000000007 RDX: 0000000000000002 RSI: 0000000000000300 RDI: ffff88810b172a00 RBP: ffff88810b172a00 R08: ffff888104273c00 R09: 0000000000100007 R10: 0000000000020000 R11: 0000000000000006 R12: ffff88810b172a00 R13: 0000000000000004 R14: 0000000000000000 R15: ffff888237c31f78 FS: 0000000000000000(0000) GS:ffff888237c00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007ffc63fecac8 CR3: 000000000342e000 CR4: 00000000000006f0 DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000 DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400 Call Trace: <TASK> ? __warn+0x88/0x130 ? inet_sock_destruct+0x1c5/0x1e0 ? report_bug+0x18e/0x1a0 ? handle_bug+0x53/0x90 ? exc_invalid_op+0x18/0x70 ? asm_exc_invalid_op+0x1a/0x20 ? inet_sock_destruct+0x1c5/0x1e0 __sk_destruct+0x2a/0x200 rcu_do_batch+0x1aa/0x530 ? rcu_do_batch+0x13b/0x530 rcu_core+0x159/0x2f0 handle_softirqs+0xd3/0x2b0 ? __pfx_smpboot_thread_fn+0x10/0x10 run_ksoftirqd+0x25/0x30 smpboot_thread_fn+0xdd/0x1d0 kthread+0xd3/0x100 ? __pfx_kthread+0x10/0x10 ret_from_fork+0x34/0x50 ? __pfx_kthread+0x10/0x10 ret_from_fork_asm+0x1a/0x30 </TASK> ---[ end trace 0000000000000000 ]--- Its possible that two threads call tcp_v6_do_rcv()/sk_forward_alloc_add() concurrently when sk->sk_state == TCP_LISTEN with sk->sk_lock unlocked, which triggers a data-race around sk->sk_forward_alloc: tcp_v6_rcv tcp_v6_do_rcv skb_clone_and_charge_r sk_rmem_schedule __sk_mem_schedule sk_forward_alloc_add() skb_set_owner_r sk_mem_charge sk_forward_alloc_add() __kfree_skb skb_release_all skb_release_head_state sock_rfree sk_mem_uncharge sk_forward_alloc_add() sk_mem_reclaim // set local var reclaimable __sk_mem_reclaim sk_forward_alloc_add() In this syzkaller testcase, two threads call tcp_v6_do_rcv() with skb->truesize=768, the sk_forward_alloc changes like this: (cpu 1) | (cpu 2) | sk_forward_alloc ... | ... | 0 __sk_mem_schedule() | | +4096 = 4096 | __sk_mem_schedule() | +4096 = 8192 sk_mem_charge() | | -768 = 7424 | sk_mem_charge() | -768 = 6656 ... | ... | sk_mem_uncharge() | | +768 = 7424 reclaimable=7424 | | | sk_mem_uncharge() | +768 = 8192 | reclaimable=8192 | __sk_mem_reclaim() | | -4096 = 4096 | __sk_mem_reclaim() | -8192 = -4096 != 0 The skb_clone_and_charge_r() should not be called in tcp_v6_do_rcv() when sk->sk_state is TCP_LISTEN, it happens later in tcp_v6_syn_recv_sock(). Fix the same issue in dccp_v6_do_rcv().
    Impacted products
    Vendor Product Version
    Linux Linux Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < 695fb0b9aecfd5dd5b2946ba8897ac2c1eef654d (git)
    Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < fe2c0bd6d1e29ccefdc978b9a290571c93c27473 (git)
    Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < c3d052cae566ec2285f5999958a5deb415a0f59e (git)
    Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < be7c61ea5f816168c38955eb4e898adc8b4b32fd (git)
    Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < 3f51f8c9d28954cf380100883a02eed35a8277e9 (git)
    Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < d285eb9d0641c8344f2836081b4ccb7b3c5cc1b6 (git)
    Affected: e994b2f0fb9229aeff5eea9541320bd7b2ca8714 , < 073d89808c065ac4c672c0a613a71b27a80691cb (git)
    Create a notification for this product.
    Linux Linux Affected: 4.4
    Unaffected: 0 , < 4.4 (semver)
    Unaffected: 5.4.290 , ≤ 5.4.* (semver)
    Unaffected: 5.10.234 , ≤ 5.10.* (semver)
    Unaffected: 5.15.177 , ≤ 5.15.* (semver)
    Unaffected: 6.1.127 , ≤ 6.1.* (semver)
    Unaffected: 6.6.74 , ≤ 6.6.* (semver)
    Unaffected: 6.11.10 , ≤ 6.11.* (semver)
    Unaffected: 6.12 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.6 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP Affected: V3.1.6 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.6 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.0 , < V3.1.5 (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP Affected: V3.1.0 , < V3.1.5 (custom)
    Create a notification for this product.
    Siemens SIPLUS S7-1500 CPU 1518-4 PN/DP MFP Affected: V3.1.0 , < V3.1.5 (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-03T20:46:04.223Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.6",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.6",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.6",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.6",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "V3.1.6",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "V3.1.5",
                    "status": "affected",
                    "version": "V3.1.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T08:39:37.903Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-398330.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "net/dccp/ipv6.c",
                "net/ipv6/tcp_ipv6.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "695fb0b9aecfd5dd5b2946ba8897ac2c1eef654d",
                  "status": "affected",
                  "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                  "versionType": "git"
                },
                {
                  "lessThan": "fe2c0bd6d1e29ccefdc978b9a290571c93c27473",
                  "status": "affected",
                  "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                  "versionType": "git"
                },
                {
                  "lessThan": "c3d052cae566ec2285f5999958a5deb415a0f59e",
                  "status": "affected",
                  "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                  "versionType": "git"
                },
                {
                  "lessThan": "be7c61ea5f816168c38955eb4e898adc8b4b32fd",
                  "status": "affected",
                  "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                  "versionType": "git"
                },
                {
                  "lessThan": "3f51f8c9d28954cf380100883a02eed35a8277e9",
                  "status": "affected",
                  "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                  "versionType": "git"
                },
                {
                  "lessThan": "d285eb9d0641c8344f2836081b4ccb7b3c5cc1b6",
                  "status": "affected",
                  "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                  "versionType": "git"
                },
                {
                  "lessThan": "073d89808c065ac4c672c0a613a71b27a80691cb",
                  "status": "affected",
                  "version": "e994b2f0fb9229aeff5eea9541320bd7b2ca8714",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "net/dccp/ipv6.c",
                "net/ipv6/tcp_ipv6.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.4"
                },
                {
                  "lessThan": "4.4",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.290",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.234",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.177",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.127",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.74",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.11.*",
                  "status": "unaffected",
                  "version": "6.11.10",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.12",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.290",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.234",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.177",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.127",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.74",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.11.10",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.12",
                      "versionStartIncluding": "4.4",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: fix data-races around sk-\u003esk_forward_alloc\n\nSyzkaller reported this warning:\n ------------[ cut here ]------------\n WARNING: CPU: 0 PID: 16 at net/ipv4/af_inet.c:156 inet_sock_destruct+0x1c5/0x1e0\n Modules linked in:\n CPU: 0 UID: 0 PID: 16 Comm: ksoftirqd/0 Not tainted 6.12.0-rc5 #26\n Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014\n RIP: 0010:inet_sock_destruct+0x1c5/0x1e0\n Code: 24 12 4c 89 e2 5b 48 c7 c7 98 ec bb 82 41 5c e9 d1 18 17 ff 4c 89 e6 5b 48 c7 c7 d0 ec bb 82 41 5c e9 bf 18 17 ff 0f 0b eb 83 \u003c0f\u003e 0b eb 97 0f 0b eb 87 0f 0b e9 68 ff ff ff 66 66 2e 0f 1f 84 00\n RSP: 0018:ffffc9000008bd90 EFLAGS: 00010206\n RAX: 0000000000000300 RBX: ffff88810b172a90 RCX: 0000000000000007\n RDX: 0000000000000002 RSI: 0000000000000300 RDI: ffff88810b172a00\n RBP: ffff88810b172a00 R08: ffff888104273c00 R09: 0000000000100007\n R10: 0000000000020000 R11: 0000000000000006 R12: ffff88810b172a00\n R13: 0000000000000004 R14: 0000000000000000 R15: ffff888237c31f78\n FS:  0000000000000000(0000) GS:ffff888237c00000(0000) knlGS:0000000000000000\n CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n CR2: 00007ffc63fecac8 CR3: 000000000342e000 CR4: 00000000000006f0\n DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000\n DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400\n Call Trace:\n  \u003cTASK\u003e\n  ? __warn+0x88/0x130\n  ? inet_sock_destruct+0x1c5/0x1e0\n  ? report_bug+0x18e/0x1a0\n  ? handle_bug+0x53/0x90\n  ? exc_invalid_op+0x18/0x70\n  ? asm_exc_invalid_op+0x1a/0x20\n  ? inet_sock_destruct+0x1c5/0x1e0\n  __sk_destruct+0x2a/0x200\n  rcu_do_batch+0x1aa/0x530\n  ? rcu_do_batch+0x13b/0x530\n  rcu_core+0x159/0x2f0\n  handle_softirqs+0xd3/0x2b0\n  ? __pfx_smpboot_thread_fn+0x10/0x10\n  run_ksoftirqd+0x25/0x30\n  smpboot_thread_fn+0xdd/0x1d0\n  kthread+0xd3/0x100\n  ? __pfx_kthread+0x10/0x10\n  ret_from_fork+0x34/0x50\n  ? __pfx_kthread+0x10/0x10\n  ret_from_fork_asm+0x1a/0x30\n  \u003c/TASK\u003e\n ---[ end trace 0000000000000000 ]---\n\nIts possible that two threads call tcp_v6_do_rcv()/sk_forward_alloc_add()\nconcurrently when sk-\u003esk_state == TCP_LISTEN with sk-\u003esk_lock unlocked,\nwhich triggers a data-race around sk-\u003esk_forward_alloc:\ntcp_v6_rcv\n    tcp_v6_do_rcv\n        skb_clone_and_charge_r\n            sk_rmem_schedule\n                __sk_mem_schedule\n                    sk_forward_alloc_add()\n            skb_set_owner_r\n                sk_mem_charge\n                    sk_forward_alloc_add()\n        __kfree_skb\n            skb_release_all\n                skb_release_head_state\n                    sock_rfree\n                        sk_mem_uncharge\n                            sk_forward_alloc_add()\n                            sk_mem_reclaim\n                                // set local var reclaimable\n                                __sk_mem_reclaim\n                                    sk_forward_alloc_add()\n\nIn this syzkaller testcase, two threads call\ntcp_v6_do_rcv() with skb-\u003etruesize=768, the sk_forward_alloc changes like\nthis:\n (cpu 1)             | (cpu 2)             | sk_forward_alloc\n ...                 | ...                 | 0\n __sk_mem_schedule() |                     | +4096 = 4096\n                     | __sk_mem_schedule() | +4096 = 8192\n sk_mem_charge()     |                     | -768  = 7424\n                     | sk_mem_charge()     | -768  = 6656\n ...                 |    ...              |\n sk_mem_uncharge()   |                     | +768  = 7424\n reclaimable=7424    |                     |\n                     | sk_mem_uncharge()   | +768  = 8192\n                     | reclaimable=8192    |\n __sk_mem_reclaim()  |                     | -4096 = 4096\n                     | __sk_mem_reclaim()  | -8192 = -4096 != 0\n\nThe skb_clone_and_charge_r() should not be called in tcp_v6_do_rcv() when\nsk-\u003esk_state is TCP_LISTEN, it happens later in tcp_v6_syn_recv_sock().\nFix the same issue in dccp_v6_do_rcv()."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "scenarios": [
                {
                  "lang": "en",
                  "value": "AV:N - The vulnerable code is in the IPv6 TCP receive path (`tcp_v6_rcv()` \u2192 `tcp_v6_do_rcv()`), executed directly on inbound SYN packets from any remote peer; a remote attacker reaches it by sending TCP/IPv6 segments to a listening socket. The same defect exists in the DCCP IPv6 receive path.\nAC:L - The attacker controls both sides of the race by sending a burst of concurrent SYNs from different source ports/addresses, which RSS/RPS distributes across CPUs that all enter `tcp_v6_do_rcv()` on the same listener with no socket lock held. No memory layout, timing window outside attacker influence, or victim state is required, and syzkaller reproduces it routinely.\nPR:N - The racing code runs while processing a SYN on a listening socket, entirely before connection establishment or any authentication, so no credentials of any kind are needed. Setting the `IPV6_RECV*` option that arms the path is done by the victim server (or by an unprivileged local user on their own listener), not by the attacker.\nUI:N - Triggering requires only that packets be sent to an already-listening socket; no action by any local user or administrator is needed.\nS:U - The corrupted state (`sk-\u003esk_forward_alloc`, `tcp_memory_allocated`, memcg skmem counters) and the resulting warning/panic are all within the kernel\u0027s own security authority, with no crossing into a hypervisor, IOMMU, or other separate authority.\nC:N - The defect is a non-atomic read-modify-write on integer accounting counters; it produces no out-of-bounds read, no use-after-free, and no path by which memory contents or kernel pointers are disclosed to the attacker.\nI:N - No attacker-controlled data is written and no memory corruption primitive is created \u2014 only the socket\u0027s own memory-accounting counters become inconsistent, which is not a modification of protected data or control flow.\nA:H - The imbalance trips `WARN_ON_ONCE(sk_forward_alloc_get(sk))` in `inet_sock_destruct()` from softirq context, which is an immediate kernel panic on `panic_on_warn` systems, and the over-reclaim corrupts the global `tcp_memory_allocated` counter and memcg skmem accounting, breaking system-wide TCP memory limits (unbounded growth toward OOM, or permanent memory pressure across all TCP sockets). It is repeatable at will by an unauthenticated remote attacker."
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-05T11:43:54.069Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/695fb0b9aecfd5dd5b2946ba8897ac2c1eef654d"
            },
            {
              "url": "https://git.kernel.org/stable/c/fe2c0bd6d1e29ccefdc978b9a290571c93c27473"
            },
            {
              "url": "https://git.kernel.org/stable/c/c3d052cae566ec2285f5999958a5deb415a0f59e"
            },
            {
              "url": "https://git.kernel.org/stable/c/be7c61ea5f816168c38955eb4e898adc8b4b32fd"
            },
            {
              "url": "https://git.kernel.org/stable/c/3f51f8c9d28954cf380100883a02eed35a8277e9"
            },
            {
              "url": "https://git.kernel.org/stable/c/d285eb9d0641c8344f2836081b4ccb7b3c5cc1b6"
            },
            {
              "url": "https://git.kernel.org/stable/c/073d89808c065ac4c672c0a613a71b27a80691cb"
            }
          ],
          "title": "net: fix data-races around sk-\u003esk_forward_alloc",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-53124",
        "datePublished": "2024-12-02T13:44:54.257Z",
        "dateReserved": "2024-11-19T17:17:24.995Z",
        "dateUpdated": "2026-09-08T08:39:37.903Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-26982 (GCVE-0-2024-26982)

    Vulnerability from cvelistv5 – Published: 2024-05-01 05:27 – Updated: 2026-05-12 11:50
    VLAI
    Title
    Squashfs: check the inode number is not the invalid value of zero
    Summary
    In the Linux kernel, the following vulnerability has been resolved: Squashfs: check the inode number is not the invalid value of zero Syskiller has produced an out of bounds access in fill_meta_index(). That out of bounds access is ultimately caused because the inode has an inode number with the invalid value of zero, which was not checked. The reason this causes the out of bounds access is due to following sequence of events: 1. Fill_meta_index() is called to allocate (via empty_meta_index()) and fill a metadata index. It however suffers a data read error and aborts, invalidating the newly returned empty metadata index. It does this by setting the inode number of the index to zero, which means unused (zero is not a valid inode number). 2. When fill_meta_index() is subsequently called again on another read operation, locate_meta_index() returns the previous index because it matches the inode number of 0. Because this index has been returned it is expected to have been filled, and because it hasn't been, an out of bounds access is performed. This patch adds a sanity check which checks that the inode number is not zero when the inode is created and returns -EINVAL if it is. [phillip@squashfs.org.uk: whitespace fix]
    Severity
    No CVSS data available.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-10 15:45 UTC
    Impacted products
    Vendor Product Version
    Linux Linux Affected: 6545b246a2c815a8fcd07d58240effb6ec3481b1 , < 32c114a58236fe67141634774559f21f1dc96fd7 (git)
    Affected: 6545b246a2c815a8fcd07d58240effb6ec3481b1 , < 4a1b6f89825e267e156ccaeba3d235edcac77f94 (git)
    Affected: 6545b246a2c815a8fcd07d58240effb6ec3481b1 , < cf46f88b92cfc0e32bd8a21ba1273cff13b8745f (git)
    Affected: 6545b246a2c815a8fcd07d58240effb6ec3481b1 , < 5b99dea79650b50909c50aba24fbae00f203f013 (git)
    Affected: 6545b246a2c815a8fcd07d58240effb6ec3481b1 , < be383effaee3d89034f0828038f95065b518772e (git)
    Affected: 6545b246a2c815a8fcd07d58240effb6ec3481b1 , < 7def00ebc9f2d6a581ddf46ce4541f84a10680e5 (git)
    Affected: 6545b246a2c815a8fcd07d58240effb6ec3481b1 , < 9253c54e01b6505d348afbc02abaa4d9f8a01395 (git)
    Create a notification for this product.
    Linux Linux Affected: 2.6.29
    Unaffected: 0 , < 2.6.29 (semver)
    Unaffected: 5.4.291 , ≤ 5.4.* (semver)
    Unaffected: 5.10.235 , ≤ 5.10.* (semver)
    Unaffected: 5.15.179 , ≤ 5.15.* (semver)
    Unaffected: 6.1.130 , ≤ 6.1.* (semver)
    Unaffected: 6.6.30 , ≤ 6.6.* (semver)
    Unaffected: 6.8.8 , ≤ 6.8.* (semver)
    Unaffected: 6.9 , ≤ * (original_commit_for_fix)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - BIOS Affected: 0 , < * (custom)
    Create a notification for this product.
    Siemens SIMATIC S7-1500 TM MFP - GNU/Linux subsystem Affected: 0 , < * (custom)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2025-11-04T17:15:00.359Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/be383effaee3d89034f0828038f95065b518772e"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/7def00ebc9f2d6a581ddf46ce4541f84a10680e5"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://git.kernel.org/stable/c/9253c54e01b6505d348afbc02abaa4d9f8a01395"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html"
              },
              {
                "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"
              },
              {
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DAMSOZXJEPUOXW33WZYWCVAY7Z5S7OOY/"
              },
              {
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4EZ6PJW7VOZ224TD7N4JZNU6KV32ZJ53/"
              },
              {
                "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GCBZZEC7L7KTWWAS2NLJK6SO3IZIL4WW/"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-26982",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-10T15:45:06.926436Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-11T17:33:42.999Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "affected": [
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - BIOS",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "defaultStatus": "unknown",
                "product": "SIMATIC S7-1500 TM MFP - GNU/Linux subsystem",
                "vendor": "Siemens",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-05-12T11:50:59.992Z",
              "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
              "shortName": "siemens-SADP"
            },
            "references": [
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-265688.html"
              },
              {
                "url": "https://cert-portal.siemens.com/productcert/html/ssa-503939.html"
              }
            ],
            "x_adpType": "supplier"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Linux",
              "programFiles": [
                "fs/squashfs/inode.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "lessThan": "32c114a58236fe67141634774559f21f1dc96fd7",
                  "status": "affected",
                  "version": "6545b246a2c815a8fcd07d58240effb6ec3481b1",
                  "versionType": "git"
                },
                {
                  "lessThan": "4a1b6f89825e267e156ccaeba3d235edcac77f94",
                  "status": "affected",
                  "version": "6545b246a2c815a8fcd07d58240effb6ec3481b1",
                  "versionType": "git"
                },
                {
                  "lessThan": "cf46f88b92cfc0e32bd8a21ba1273cff13b8745f",
                  "status": "affected",
                  "version": "6545b246a2c815a8fcd07d58240effb6ec3481b1",
                  "versionType": "git"
                },
                {
                  "lessThan": "5b99dea79650b50909c50aba24fbae00f203f013",
                  "status": "affected",
                  "version": "6545b246a2c815a8fcd07d58240effb6ec3481b1",
                  "versionType": "git"
                },
                {
                  "lessThan": "be383effaee3d89034f0828038f95065b518772e",
                  "status": "affected",
                  "version": "6545b246a2c815a8fcd07d58240effb6ec3481b1",
                  "versionType": "git"
                },
                {
                  "lessThan": "7def00ebc9f2d6a581ddf46ce4541f84a10680e5",
                  "status": "affected",
                  "version": "6545b246a2c815a8fcd07d58240effb6ec3481b1",
                  "versionType": "git"
                },
                {
                  "lessThan": "9253c54e01b6505d348afbc02abaa4d9f8a01395",
                  "status": "affected",
                  "version": "6545b246a2c815a8fcd07d58240effb6ec3481b1",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "affected",
              "product": "Linux",
              "programFiles": [
                "fs/squashfs/inode.c"
              ],
              "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
              "vendor": "Linux",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.6.29"
                },
                {
                  "lessThan": "2.6.29",
                  "status": "unaffected",
                  "version": "0",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.4.*",
                  "status": "unaffected",
                  "version": "5.4.291",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.10.*",
                  "status": "unaffected",
                  "version": "5.10.235",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "5.15.*",
                  "status": "unaffected",
                  "version": "5.15.179",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.1.*",
                  "status": "unaffected",
                  "version": "6.1.130",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.6.*",
                  "status": "unaffected",
                  "version": "6.6.30",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "6.8.*",
                  "status": "unaffected",
                  "version": "6.8.8",
                  "versionType": "semver"
                },
                {
                  "lessThanOrEqual": "*",
                  "status": "unaffected",
                  "version": "6.9",
                  "versionType": "original_commit_for_fix"
                }
              ]
            }
          ],
          "cpeApplicability": [
            {
              "nodes": [
                {
                  "cpeMatch": [
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.4.291",
                      "versionStartIncluding": "2.6.29",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.10.235",
                      "versionStartIncluding": "2.6.29",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "5.15.179",
                      "versionStartIncluding": "2.6.29",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.1.130",
                      "versionStartIncluding": "2.6.29",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.6.30",
                      "versionStartIncluding": "2.6.29",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.8.8",
                      "versionStartIncluding": "2.6.29",
                      "vulnerable": true
                    },
                    {
                      "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                      "versionEndExcluding": "6.9",
                      "versionStartIncluding": "2.6.29",
                      "vulnerable": true
                    }
                  ],
                  "negate": false,
                  "operator": "OR"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nSquashfs: check the inode number is not the invalid value of zero\n\nSyskiller has produced an out of bounds access in fill_meta_index().\n\nThat out of bounds access is ultimately caused because the inode\nhas an inode number with the invalid value of zero, which was not checked.\n\nThe reason this causes the out of bounds access is due to following\nsequence of events:\n\n1. Fill_meta_index() is called to allocate (via empty_meta_index())\n   and fill a metadata index.  It however suffers a data read error\n   and aborts, invalidating the newly returned empty metadata index.\n   It does this by setting the inode number of the index to zero,\n   which means unused (zero is not a valid inode number).\n\n2. When fill_meta_index() is subsequently called again on another\n   read operation, locate_meta_index() returns the previous index\n   because it matches the inode number of 0.  Because this index\n   has been returned it is expected to have been filled, and because\n   it hasn\u0027t been, an out of bounds access is performed.\n\nThis patch adds a sanity check which checks that the inode number\nis not zero when the inode is created and returns -EINVAL if it is.\n\n[phillip@squashfs.org.uk: whitespace fix]"
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-05-11T20:08:07.235Z",
            "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "shortName": "Linux"
          },
          "references": [
            {
              "url": "https://git.kernel.org/stable/c/32c114a58236fe67141634774559f21f1dc96fd7"
            },
            {
              "url": "https://git.kernel.org/stable/c/4a1b6f89825e267e156ccaeba3d235edcac77f94"
            },
            {
              "url": "https://git.kernel.org/stable/c/cf46f88b92cfc0e32bd8a21ba1273cff13b8745f"
            },
            {
              "url": "https://git.kernel.org/stable/c/5b99dea79650b50909c50aba24fbae00f203f013"
            },
            {
              "url": "https://git.kernel.org/stable/c/be383effaee3d89034f0828038f95065b518772e"
            },
            {
              "url": "https://git.kernel.org/stable/c/7def00ebc9f2d6a581ddf46ce4541f84a10680e5"
            },
            {
              "url": "https://git.kernel.org/stable/c/9253c54e01b6505d348afbc02abaa4d9f8a01395"
            }
          ],
          "title": "Squashfs: check the inode number is not the invalid value of zero",
          "x_generator": {
            "engine": "bippy-1.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "assignerShortName": "Linux",
        "cveId": "CVE-2024-26982",
        "datePublished": "2024-05-01T05:27:11.032Z",
        "dateReserved": "2024-02-19T14:20:24.204Z",
        "dateUpdated": "2026-05-12T11:50:59.992Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }