目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-38112— Linux kernel 安全漏洞

AI Predicted 4.9 Difficulty: Hard EPSS 0.12% · P2

Affected Version Matrix 16

ベンダープロダクトVersion Rangeステータス
LinuxLinux8934ce2fd08171e8605f7fada91ee7619fe17ab8< c2b26638476baee154920bb587fc94ff1bf04336affected
8934ce2fd08171e8605f7fada91ee7619fe17ab8< 6fa68d7eab34d448a61aa24ea31e68b3231ed20daffected
8934ce2fd08171e8605f7fada91ee7619fe17ab8< 8926a7ef1977a832dd6bf702f1a99303dbf15b15affected
8934ce2fd08171e8605f7fada91ee7619fe17ab8< ff55c85a923e043d59d26b20a673a1b4a219c310affected
8934ce2fd08171e8605f7fada91ee7619fe17ab8< 1e0de7582ceccbdbb227d4e0ddf65732f92526daaffected
8934ce2fd08171e8605f7fada91ee7619fe17ab8< 1b367ba2f94251822577daed031d6b9a9e11ba91affected
8934ce2fd08171e8605f7fada91ee7619fe17ab8< 2660a544fdc0940bba15f70508a46cf9a6491230affected
4.17affected
… +8 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-38112の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
net: Fix TOCTOU issue in sk_is_readable()
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: net: Fix TOCTOU issue in sk_is_readable() sk->sk_prot->sock_is_readable is a valid function pointer when sk resides in a sockmap. After the last sk_psock_put() (which usually happens when socket is removed from sockmap), sk->sk_prot gets restored and sk->sk_prot->sock_is_readable becomes NULL. This makes sk_is_readable() racy, if the value of sk->sk_prot is reloaded after the initial check. Which in turn may lead to a null pointer dereference. Ensure the function pointer does not turn NULL after the check.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于sk_is_readable函数存在TOCTOU问题,可能导致空指针取消引用。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 8934ce2fd08171e8605f7fada91ee7619fe17ab8 ~ c2b26638476baee154920bb587fc94ff1bf04336 -
LinuxLinux 4.17 -

II. CVE-2025-38112の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-38112のインテリジェンス情報

登录查看更多情报信息。

CVE-2025-38112 补丁与修复 (1)

Same Patch Batch · Linux · 2025-07-03 · 78 CVEs total

CVE-2025-38129page_pool: Fix use-after-free in page_pool_recycle_in_ring
CVE-2025-38128Bluetooth: MGMT: reject malformed HCI_CMD_SYNC commands
CVE-2025-38114e1000: Move cancel_work_sync to avoid deadlock
CVE-2025-38127ice: fix Tx scheduler error handling in XDP callback
CVE-2025-38125net: stmmac: make sure that ptp_rate is not 0 before configuring EST
CVE-2025-38126net: stmmac: make sure that ptp_rate is not 0 before configuring timestamping
CVE-2025-38130drm/connector: only call HDMI audio helper plugged cb if non-null
CVE-2025-38131coresight: prevent deactivate active config while enabling the config
CVE-2025-38132coresight: holding cscfg_csdev_lock while removing cscfg from csdev
CVE-2025-38133iio: adc: ad4851: fix ad4858 chan pointer handling
CVE-2025-38124net: fix udp gso skb_segment after pull from frag_list
CVE-2025-38122gve: add missing NULL check for gve_alloc_pending_packet() in TX DQO
CVE-2025-38123net: wwan: t7xx: Fix napi rx poll issue
CVE-2025-38121wifi: iwlwifi: mld: avoid panic on init failure
CVE-2025-38119scsi: core: ufs: Fix a hang in the error handler
CVE-2025-38120netfilter: nf_set_pipapo_avx2: fix initial map fill
CVE-2025-38118Bluetooth: MGMT: Fix UAF on mgmt_remove_adv_monitor_complete
CVE-2025-38117Bluetooth: MGMT: Protect mgmt_pending list with its own lock
CVE-2025-38115net_sched: sch_sfq: fix a potential crash on gso_skb handling
CVE-2025-38116wifi: ath12k: fix uaf in ath12k_core_init()

Showing 20 of 78 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2025-38112へのコメント

まだコメントはありません


コメントを残す