cbcvebase.
CVE-2025-40231
published 2025-12-04

CVE-2025-40231: In the Linux kernel, the following vulnerability has been resolved: vsock: fix lock inversion in vsock_assign_transport() Syzbot reported a potential lock…

PriorityP420high7.8
EPSS
0.20%
10.3th percentile
In the Linux kernel, the following vulnerability has been resolved: vsock: fix lock inversion in vsock_assign_transport() Syzbot reported a potential lock inversion deadlock between vsock_register_mutex and sk_lock-AF_VSOCK when vsock_linger() is called. The issue was introduced by commit 687aa0c5581b ("vsock: Fix transport_* TOCTOU") which added vsock_register_mutex locking in vsock_assign_transport() around the transport->release() call, that can call vsock_linger(). vsock_assign_transport() can be called with sk_lock held. vsock_linger() calls sk_wait_event() that temporarily releases and re-acquires sk_lock. During this window, if another thread hold vsock_register_mutex while trying to acquire sk_lock, a circular dependency is created. Fix this by releasing vsock_register_mutex before calling transport->release() and vsock_deassign_transport(). This is safe because we don't need to hold vsock_register_mutex while releasing the old transport, and we ensure the new transport won't disappear by obtaining a module reference first via try_module_get().

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 36a439049b34cca0b3661276049b84a1f76cc21a < 09bba278ccde25a14b6e5088a9e65a8717d0cccf09bba278ccde25a14b6e5088a9e65a8717d0cccf
linuxlinux>= 5.10.240 < 5.10.2465.10.246
linuxlinux>= 5.15.189 < 5.15.1965.15.196
linuxlinux>= 6.1.146 < 6.1.1586.1.158
linuxlinux>= 6.12.39 < 6.12.566.12.56
linuxlinux>= 6.15.7 < 6.166.16
linuxlinux>= 6.6.99 < 6.6.1156.6.115
linuxlinux>= 687aa0c5581b8d4aa87fd92973e4ee576b550cdf < a2a4346eea8b4cb75037dbcb20b98cb454324f80a2a4346eea8b4cb75037dbcb20b98cb454324f80
linuxlinux>= 687aa0c5581b8d4aa87fd92973e4ee576b550cdf < f7c877e7535260cc7a21484c994e8ce7e8cb6780f7c877e7535260cc7a21484c994e8ce7e8cb6780
linuxlinux>= 8667e8d0eb46bc54fdae30ba2f4786407d3d88eb < ce4f856c64f0bc30e29302a0ce41f4295ca391c5ce4f856c64f0bc30e29302a0ce41f4295ca391c5
linuxlinux>= 9ce53e744f18e73059d3124070e960f3aa9902bf < b44182c116778feaa05da52a426aeb9da1878dcfb44182c116778feaa05da52a426aeb9da1878dcf
linuxlinux>= 9d24bb6780282b0255b9929abe5e8f98007e2c6e < 42ed0784d11adebf748711e503af0eb9f1e6d81d42ed0784d11adebf748711e503af0eb9f1e6d81d
linuxlinux>= ae2c712ba39c7007de63cb0c75b51ce1caaf1da5 < 251caee792a21eb0b781aab91362b422c945e162251caee792a21eb0b781aab91362b422c945e162
linuxlinux_kernel>= 0 < 5.10.247-15.10.247-1
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 5.10.2465.10.246
linuxlinux_kernel>= 0 < 5.15.0-170.1805.15.0-170.180
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 5.11.0 < 5.15.1965.15.196

CVSS provenance

osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.