Executive brief
A vulnerability in the Linux kernel's Asynchronous Transfer Mode (ATM) over TCP implementation could allow a local user to perform unauthorized memory writes. This component is used for legacy networking protocols. An attacker could exploit this flaw to crash the system or potentially gain elevated privileges, compromising the integrity and availability of the operating system.
Technical details
A vulnerability exists in the atmtcp driver within the Linux kernel where atmtcp_recv_control() fails to properly validate message lengths from userspace via sendmsg(). The atmtcp_control structure, while part of the user API (uAPI), contains a field for an in-kernel pointer (vcc). Because sendmsg() does not verify that the message length is appropriate for the expected control structure, a local attacker can craft a malicious message that triggers an arbitrary write to kernel memory. This is achieved by abusing the processing of 'special' messages identified by ATMTCP_HDR_MAGIC. The fix introduces a pre_send hook to validate message headers and lengths before they are processed by the control handler.
Affected products
- Linux Linux Kernel 2.6.12-rc2 through 6.17.0-rc1
Timeline
- 2025-08-21: patched: Initial patch submitted by Kuniyuki Iwashima
- 2025-09-16: advisory: CVE-2025-39828 published
References
- https://git.kernel.org/stable/c/0a6a6d4fb333f7afe22e59ffed18511a7a98efc8
- https://git.kernel.org/stable/c/33f9e6dc66b32202b95fc861e6b3ea4b0c185b0b
- https://git.kernel.org/stable/c/3ab9f5ad9baefe6d3d4c37053cdfca2761001dfe
- https://git.kernel.org/stable/c/3c80c230d6e3e6f63d43f4c3f0bb344e3e8b119b
- https://git.kernel.org/stable/c/51872b26429077be611b0a1816e0e722278015c3
- https://git.kernel.org/stable/c/62f368472b0aa4b5d91d9b983152855c6b6d8925
- https://git.kernel.org/stable/c/b502f16bad8f0a4cfbd023452766f21bfda39dde