PT-2025-27736 · Linux+1 · Linux Kernel+1
CVE-2025-38150
·
Published
2025-05-21
·
Updated
2025-07-03
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
A vulnerability in the Linux kernel has been resolved. The issue is related to the
af packet module, where calling PACKET ADD MEMBERSHIP on an ops-locked device can trigger the NETDEV UNREGISTER notifier, requiring the acquisition of the netdev instance lock. This can lead to a sleeping function being called from an invalid context. The mclist modifications are protected by the RTNL, not the RCU.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Time Of Check To Time Of Use
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel