PT-2025-16924 · Google · Kernel

Published

2025-04-17

·

Updated

2025-07-11

·

CVE-2025-1290

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kernel versions prior to the fixed version
Description A race condition Use-After-Free issue exists in the virtio transport space update function within the Kernel on ChromeOS. This occurs due to concurrent allocation and freeing of the virtio vsock sock structure during an AF VSOCK connect syscall, which can result in a dangling pointer and potential kernel code execution.
Recommendations For versions prior to the fixed version, consider applying a patch that fixes the race condition in the virtio transport space update function to prevent the Use-After-Free vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2025-1290

Affected Products

Kernel