cbcvebase.
CVE-2025-23163
published 2025-05-01

CVE-2025-23163: In the Linux kernel, the following vulnerability has been resolved: net: vlan: don't propagate flags on open With the device instance lock, there is now a…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
4.3th percentile
In the Linux kernel, the following vulnerability has been resolved: net: vlan: don't propagate flags on open With the device instance lock, there is now a possibility of a deadlock: [ 1.211455] ============================================ [ 1.211571] WARNING: possible recursive locking detected [ 1.211687] 6.14.0-rc5-01215-g032756b4ca7a-dirty #5 Not tainted [ 1.211823] -------------------------------------------- [ 1.211936] ip/184 is trying to acquire lock: [ 1.212032] ffff8881024a4c30 (&dev->lock){+.+.}-{4:4}, at: dev_set_allmulti+0x4e/0xb0 [ 1.212207] [ 1.212207] but task is already holding lock: [ 1.212332] ffff8881024a4c30 (&dev->lock){+.+.}-{4:4}, at: dev_open+0x50/0xb0 [ 1.212487] [ 1.212487] other info that might help us debug this: [ 1.212626] Possible unsafe locking scenario: [ 1.212626] [ 1.212751] CPU0 [ 1.212815] ---- [ 1.212871] lock(&dev->lock); [ 1.212944] lock(&dev->lock); [ 1.213016] [ 1.213016] *** DEADLOCK *** [ 1.213016] [ 1.213143] May be due to missing lock nesting notation [ 1.213143] [ 1.213294] 3 locks held by ip/184: [ 1.213371] #0: ffffffff838b53e0 (rtnl_mutex){+.+.}-{4:4}, at: rtnl_nets_lock+0x1b/0xa0 [ 1.213543] #1: ffffffff84e5fc70 (&net->rtnl_mutex){+.+.}-{4:4}, at: rtnl_nets_lock+0x37/0xa0 [ 1.213727] #2: ffff8881024a4c30 (&dev->lock){+.+.}-{4:4}, at: dev_open+0x50/0xb0 [ 1.213895] [ 1.213895] stack backtrace: [ 1.213991] CPU: 0 UID: 0 PID: 184 Comm: ip Not tainted 6.14.0-rc5-01215-g032756b4ca7a-dirty #5 [ 1.213993] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS Arch Linux 1.16.3-1-1 04/01/2014 [ 1.213994] Call Trace: [ 1.213995] [ 1.213996] dump_stack_lvl+0x8e/0xd0 [ 1.214000] print_deadlock_bug+0x28b/0x2a0 [ 1.214020] lock_acquire+0xea/0x2a0 [ 1.214027] __mutex_lock+0xbf/0xd40 [ 1.214038] dev_set_allmulti+0x4e/0xb0 # real_dev->flags & IFF_ALLMULTI [ 1.214040] vlan_dev_open+0xa5/0x170 # ndo_open on vlandev [ 1.214042] __dev_open+0x145/0x270 [ 1.214046] __dev_change_flags+0xb0/0x1e0 [ 1.214051] netif_change_flags+0x22

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 6c78dcbd47a68a7d25d2bee7a6c74b9136cb5fde < a32f1d4f1f4c9d978698f3c718621f6198f2e7aca32f1d4f1f4c9d978698f3c718621f6198f2e7ac
linuxlinux>= 6c78dcbd47a68a7d25d2bee7a6c74b9136cb5fde < b1e3eeb037256a2f1206a8d69810ec47eb152026b1e3eeb037256a2f1206a8d69810ec47eb152026
linuxlinux>= 6c78dcbd47a68a7d25d2bee7a6c74b9136cb5fde < 523fa0979d842443aa14b80002e45b471cbac137523fa0979d842443aa14b80002e45b471cbac137
linuxlinux>= 6c78dcbd47a68a7d25d2bee7a6c74b9136cb5fde < 53fb25e90c0a503a17c639341ba5e755cb2feb5c53fb25e90c0a503a17c639341ba5e755cb2feb5c
linuxlinux>= 6c78dcbd47a68a7d25d2bee7a6c74b9136cb5fde < d537859e56bcc3091805c524484a4c85386b3cc8d537859e56bcc3091805c524484a4c85386b3cc8
linuxlinux>= 6c78dcbd47a68a7d25d2bee7a6c74b9136cb5fde < 299d7d27af6b5844cda06a0fdfa635705e1bc50f299d7d27af6b5844cda06a0fdfa635705e1bc50f
linuxlinux>= 6c78dcbd47a68a7d25d2bee7a6c74b9136cb5fde < 8980018a9806743d9b80837330d46f06ecf785168980018a9806743d9b80837330d46f06ecf78516
linuxlinux>= 6c78dcbd47a68a7d25d2bee7a6c74b9136cb5fde < 538b43aa21e3b17c110104efd218b966d2eda5f8538b43aa21e3b17c110104efd218b966d2eda5f8
linuxlinux>= 6c78dcbd47a68a7d25d2bee7a6c74b9136cb5fde < 27b918007d96402aba10ed52a6af8015230f179327b918007d96402aba10ed52a6af8015230f1793
linuxlinux_kernel< 5.4.2935.4.293
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1356.1.135
linuxlinux_kernel>= 5.5 < 5.10.2375.10.237
linuxlinux_kernel>= 6.13 < 6.13.126.13.12

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.