cbcvebase.
CVE-2025-21666
published 2025-01-31

CVE-2025-21666: In the Linux kernel, the following vulnerability has been resolved: vsock: prevent null-ptr-deref in vsock_*[has_data|has_space] Recent reports have shown how…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.5th percentile
In the Linux kernel, the following vulnerability has been resolved: vsock: prevent null-ptr-deref in vsock_*[has_data|has_space] Recent reports have shown how we sometimes call vsock_*_has_data() when a vsock socket has been de-assigned from a transport (see attached links), but we shouldn't. Previous commits should have solved the real problems, but we may have more in the future, so to avoid null-ptr-deref, we can return 0 (no space, no data available) but with a warning. This way the code should continue to run in a nearly consistent state and have a warning that allows us to debug future problems.

Affected

20 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux>= c0cfa2d8a788fcf45df5bf4070ab2474c88d543a < daeac89cdb03d30028186f5ff7dc26ec8fa843e7daeac89cdb03d30028186f5ff7dc26ec8fa843e7
linuxlinux>= c0cfa2d8a788fcf45df5bf4070ab2474c88d543a < 9e5fed46ccd2c34c5fa5a9c8825ce4823fdc853e9e5fed46ccd2c34c5fa5a9c8825ce4823fdc853e
linuxlinux>= c0cfa2d8a788fcf45df5bf4070ab2474c88d543a < b52e50dd4fabd12944172bd486a4f4853b7f74ddb52e50dd4fabd12944172bd486a4f4853b7f74dd
linuxlinux>= c0cfa2d8a788fcf45df5bf4070ab2474c88d543a < bc9c49341f9728c31fe248c5fbba32d2e81a092bbc9c49341f9728c31fe248c5fbba32d2e81a092b
linuxlinux>= c0cfa2d8a788fcf45df5bf4070ab2474c88d543a < c23d1d4f8efefb72258e9cedce29de10d057f8cac23d1d4f8efefb72258e9cedce29de10d057f8ca
linuxlinux>= c0cfa2d8a788fcf45df5bf4070ab2474c88d543a < 91751e248256efc111e52e15115840c35d85abaf91751e248256efc111e52e15115840c35d85abaf
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1
linuxlinux_kernel>= 0 < 6.12.11-16.12.11-1
linuxlinux_kernel>= 0 < 6.12.11-16.12.11-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-62.656.8.0-62.65
linuxlinux_kernel>= 5.16 < 6.1.1276.1.127
linuxlinux_kernel>= 5.5 < 5.15.1775.15.177
linuxlinux_kernel>= 6.2 < 6.6.746.6.74
linuxlinux_kernel>= 6.7 < 6.12.116.12.11

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.