Executive brief
A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. The issue occurs when the system attempts to process data for a virtual socket that has been disconnected from its underlying transport mechanism. This results in a system crash (NULL pointer dereference), impacting the availability of the server or workstation.
Technical details
A NULL pointer dereference vulnerability exists in the Linux kernel's vsock implementation within net/vmw_vsock/af_vsock.c. The functions vsock_stream_has_data(), vsock_connectible_has_data(), and vsock_stream_has_space() fail to validate if vsk->transport is NULL before dereferencing it to call transport-specific functions. This condition can occur when a vsock socket is de-assigned from a transport while these checks are still being invoked. A local attacker can exploit this to trigger a kernel panic (DoS). The fix introduces a check for the transport pointer and returns 0 with a kernel warning if it is missing.
Affected products
- Linux Linux Kernel 5.5 to 5.15.177, 5.16 to 6.1.127, 6.2 to 6.6.74, 6.7 to 6.12.11, 6.13-rc1 to 6.13-rc7
Timeline
- 2025-01-10: patched: Initial patch authored by Stefano Garzarella
- 2025-01-31: disclosed: CVE-2025-21666 published
References
- https://git.kernel.org/stable/c/91751e248256efc111e52e15115840c35d85abaf
- https://git.kernel.org/stable/c/9e5fed46ccd2c34c5fa5a9c8825ce4823fdc853e
- https://git.kernel.org/stable/c/b52e50dd4fabd12944172bd486a4f4853b7f74dd
- https://git.kernel.org/stable/c/bc9c49341f9728c31fe248c5fbba32d2e81a092b
- https://git.kernel.org/stable/c/c23d1d4f8efefb72258e9cedce29de10d057f8ca
- https://git.kernel.org/stable/c/daeac89cdb03d30028186f5ff7dc26ec8fa843e7
- https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html