CVE-2025-40280
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/12/2025
Last modified:
06/12/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
tipc: Fix use-after-free in tipc_mon_reinit_self().<br />
<br />
syzbot reported use-after-free of tipc_net(net)->monitors[]<br />
in tipc_mon_reinit_self(). [0]<br />
<br />
The array is protected by RTNL, but tipc_mon_reinit_self()<br />
iterates over it without RTNL.<br />
<br />
tipc_mon_reinit_self() is called from tipc_net_finalize(),<br />
which is always under RTNL except for tipc_net_finalize_work().<br />
<br />
Let&#39;s hold RTNL in tipc_net_finalize_work().<br />
<br />
[0]:<br />
BUG: KASAN: slab-use-after-free in __raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]<br />
BUG: KASAN: slab-use-after-free in _raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162<br />
Read of size 1 at addr ffff88805eae1030 by task kworker/0:7/5989<br />
<br />
CPU: 0 UID: 0 PID: 5989 Comm: kworker/0:7 Not tainted syzkaller #0 PREEMPT_{RT,(full)}<br />
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 08/18/2025<br />
Workqueue: events tipc_net_finalize_work<br />
Call Trace:<br />
<br />
dump_stack_lvl+0x189/0x250 lib/dump_stack.c:120<br />
print_address_description mm/kasan/report.c:378 [inline]<br />
print_report+0xca/0x240 mm/kasan/report.c:482<br />
kasan_report+0x118/0x150 mm/kasan/report.c:595<br />
__kasan_check_byte+0x2a/0x40 mm/kasan/common.c:568<br />
kasan_check_byte include/linux/kasan.h:399 [inline]<br />
lock_acquire+0x8d/0x360 kernel/locking/lockdep.c:5842<br />
__raw_spin_lock_irqsave include/linux/spinlock_api_smp.h:110 [inline]<br />
_raw_spin_lock_irqsave+0xa7/0xf0 kernel/locking/spinlock.c:162<br />
rtlock_slowlock kernel/locking/rtmutex.c:1894 [inline]<br />
rwbase_rtmutex_lock_state kernel/locking/spinlock_rt.c:160 [inline]<br />
rwbase_write_lock+0xd3/0x7e0 kernel/locking/rwbase_rt.c:244<br />
rt_write_lock+0x76/0x110 kernel/locking/spinlock_rt.c:243<br />
write_lock_bh include/linux/rwlock_rt.h:99 [inline]<br />
tipc_mon_reinit_self+0x79/0x430 net/tipc/monitor.c:718<br />
tipc_net_finalize+0x115/0x190 net/tipc/net.c:140<br />
process_one_work kernel/workqueue.c:3236 [inline]<br />
process_scheduled_works+0xade/0x17b0 kernel/workqueue.c:3319<br />
worker_thread+0x8a0/0xda0 kernel/workqueue.c:3400<br />
kthread+0x70e/0x8a0 kernel/kthread.c:463<br />
ret_from_fork+0x439/0x7d0 arch/x86/kernel/process.c:148<br />
ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:245<br />
<br />
<br />
Allocated by task 6089:<br />
kasan_save_stack mm/kasan/common.c:47 [inline]<br />
kasan_save_track+0x3e/0x80 mm/kasan/common.c:68<br />
poison_kmalloc_redzone mm/kasan/common.c:388 [inline]<br />
__kasan_kmalloc+0x93/0xb0 mm/kasan/common.c:405<br />
kasan_kmalloc include/linux/kasan.h:260 [inline]<br />
__kmalloc_cache_noprof+0x1a8/0x320 mm/slub.c:4407<br />
kmalloc_noprof include/linux/slab.h:905 [inline]<br />
kzalloc_noprof include/linux/slab.h:1039 [inline]<br />
tipc_mon_create+0xc3/0x4d0 net/tipc/monitor.c:657<br />
tipc_enable_bearer net/tipc/bearer.c:357 [inline]<br />
__tipc_nl_bearer_enable+0xe16/0x13f0 net/tipc/bearer.c:1047<br />
__tipc_nl_compat_doit net/tipc/netlink_compat.c:371 [inline]<br />
tipc_nl_compat_doit+0x3bc/0x5f0 net/tipc/netlink_compat.c:393<br />
tipc_nl_compat_handle net/tipc/netlink_compat.c:-1 [inline]<br />
tipc_nl_compat_recv+0x83c/0xbe0 net/tipc/netlink_compat.c:1321<br />
genl_family_rcv_msg_doit+0x215/0x300 net/netlink/genetlink.c:1115<br />
genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline]<br />
genl_rcv_msg+0x60e/0x790 net/netlink/genetlink.c:1210<br />
netlink_rcv_skb+0x208/0x470 net/netlink/af_netlink.c:2552<br />
genl_rcv+0x28/0x40 net/netlink/genetlink.c:1219<br />
netlink_unicast_kernel net/netlink/af_netlink.c:1320 [inline]<br />
netlink_unicast+0x846/0xa10 net/netlink/af_netlink.c:1346<br />
netlink_sendmsg+0x805/0xb30 net/netlink/af_netlink.c:1896<br />
sock_sendmsg_nosec net/socket.c:714 [inline]<br />
__sock_sendmsg+0x21c/0x270 net/socket.c:729<br />
____sys_sendmsg+0x508/0x820 net/socket.c:2614<br />
___sys_sendmsg+0x21f/0x2a0 net/socket.c:2668<br />
__sys_sendmsg net/socket.c:2700 [inline]<br />
__do_sys_sendmsg net/socket.c:2705 [inline]<br />
__se_sys_sendmsg net/socket.c:2703 [inline]<br />
__x64_sys_sendmsg+0x1a1/0x260 net/socket.c:2703<br />
do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]<br />
do_syscall_64+0xfa/0x3b0 arch/<br />
---truncated---
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/0725e6afb55128be21a2ca36e9674f573ccec173
- https://git.kernel.org/stable/c/499b5fa78d525c4450ebb76db83207db71efea77
- https://git.kernel.org/stable/c/51b8f0ab888f8aa5dfac954918864eeda8c12c19
- https://git.kernel.org/stable/c/5f541300b02ef8b2af34f6f7d41ce617f3571e88
- https://git.kernel.org/stable/c/b2e77c789c234e7fe49057d2ced8f32e2d2c7901
- https://git.kernel.org/stable/c/c92dbf85627b5c29e52d9c120a24e785801716df
- https://git.kernel.org/stable/c/f0104977fed25ebe001fd63dab2b6b7fefad3373
- https://git.kernel.org/stable/c/fdf7c4c9af4f246323ce854e84b6aec198d49f7e



