PT-2025-27896 · Linux+3 · Linux Kernel+3

Publicado

2025-05-24

·

Atualizado

2025-12-03

·

CVE-2025-38175

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to 6.15.0-rc7-00138-g57483a362741
Description: A use-after-free vulnerability has been identified in the Linux kernel, specifically in the binder devices list. The issue arises when devices are released without being removed from the list, allowing for potential exploitation. The vulnerability was addressed by ensuring that the device is removed from the binder devices list before being freed.
Recommendations: For Linux kernel versions prior to 6.15.0-rc7-00138-g57483a362741, update to a version that includes the fix for the use-after-free vulnerability in the binder devices list. As a temporary workaround, consider restricting access to the binder remove device function until a patch is available.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-08220
CVE-2025-38175
USN-7769-1
USN-7769-2
USN-7769-3
USN-7770-1
USN-7771-1
USN-7789-1
USN-7789-2

Produtos afetados

Astra Linux
Linuxmint
Linux Kernel
Ubuntu