Junglewise Threat Intelligence

CVE-2025-21666: Linux Kernel NULL pointer dereference in vsock transport

CVE-2025-21666 · Severity: medium · CVSS 5.5 · Published 2025-01-31

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's networking component could allow a local user to crash the system. The issue occurs when the system attempts to process data for a virtual socket that has been disconnected from its underlying transport mechanism. This results in a system crash (NULL pointer dereference), impacting the availability of the server or workstation.

Technical details

A NULL pointer dereference vulnerability exists in the Linux kernel's vsock implementation within net/vmw_vsock/af_vsock.c. The functions vsock_stream_has_data(), vsock_connectible_has_data(), and vsock_stream_has_space() fail to validate if vsk->transport is NULL before dereferencing it to call transport-specific functions. This condition can occur when a vsock socket is de-assigned from a transport while these checks are still being invoked. A local attacker can exploit this to trigger a kernel panic (DoS). The fix introduces a check for the transport pointer and returns 0 with a kernel warning if it is missing.

Affected products

  • Linux Linux Kernel 5.5 to 5.15.177, 5.16 to 6.1.127, 6.2 to 6.6.74, 6.7 to 6.12.11, 6.13-rc1 to 6.13-rc7

Timeline

  • 2025-01-10: patched: Initial patch authored by Stefano Garzarella
  • 2025-01-31: disclosed: CVE-2025-21666 published

References

Related threats