cbcvebase.
CVE-2025-38003
published 2025-06-08

CVE-2025-38003: In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu read protection for procfs content When the procfs content is…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu read protection for procfs content When the procfs content is generated for a bcm_op which is in the process to be removed the procfs output might show unreliable data (UAF). As the removal of bcm_op's is already implemented with rcu handling this patch adds the missing rcu_read_lock() and makes sure the list entries are properly removed under rcu protection.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
debianlinux-6.1< linux 6.1.147-1 (bookworm)linux 6.1.147-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.19.252 < 4.204.20
linuxlinux>= 5.10.130 < 5.10.2385.10.238
linuxlinux>= 5.15.54 < 5.15.1855.15.185
linuxlinux>= 5.18.11 < 5.195.19
linuxlinux>= 5.4.205 < 5.4.2945.4.294
linuxlinux>= 5b48f5711f1c630841ab78dcc061de902f0e37bf < 19f553a1ddf260da6570ed8f8d91a8c87f49b63a19f553a1ddf260da6570ed8f8d91a8c87f49b63a
linuxlinux>= 85cd41070df992d3c0dfd828866fdd243d3b774a < 659701c0b954ccdb4a916a4ad59bbc16e726d42c659701c0b954ccdb4a916a4ad59bbc16e726d42c
linuxlinux>= f1b4e32aca0811aa011c76e5d6cf2fa19224b386 < 6d7d458c41b98a5c1670cbd36f2923c37de51cf56d7d458c41b98a5c1670cbd36f2923c37de51cf5
linuxlinux>= f1b4e32aca0811aa011c76e5d6cf2fa19224b386 < 1f912f8484e9c4396378c39460bbea0af681f3191f912f8484e9c4396378c39460bbea0af681f319
linuxlinux>= f1b4e32aca0811aa011c76e5d6cf2fa19224b386 < 63567ecd99a24495208dc860d50fb1744004300663567ecd99a24495208dc860d50fb17440043006
linuxlinux>= f1b4e32aca0811aa011c76e5d6cf2fa19224b386 < 7c9db92d5f0eadca30884af75c53d601edc512ee7c9db92d5f0eadca30884af75c53d601edc512ee
linuxlinux>= f1b4e32aca0811aa011c76e5d6cf2fa19224b386 < dac5e6249159ac255dad9781793dbe5908ac9ddbdac5e6249159ac255dad9781793dbe5908ac9ddb
linuxlinux>= f34f2a18e47b73e48f90a757e1f4aaa8c7d665a1 < 0622846db728a5332b917c797c733e202c4620ae0622846db728a5332b917c797c733e202c4620ae
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.147-16.1.147-1
linuxlinux_kernel>= 0 < 6.12.32-16.12.32-1
linuxlinux_kernel>= 0 < 6.12.32-16.12.32-1

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM