PT-2025-27736 · Linux+1 · Linux Kernel+1
Published
2025-05-21
·
Updated
2025-07-03
·
CVE-2025-38150
CVSS v2.0
6.0
Medium
| Vector | AV:L/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Linux kernel (affected versions not specified)
Description:
A vulnerability in the Linux kernel has been resolved. The issue is related to the
af packet module, where calling PACKET ADD MEMBERSHIP on an ops-locked device can trigger the NETDEV UNREGISTER notifier, requiring the acquisition of the netdev instance lock. This can lead to a sleeping function being called from an invalid context. The mclist modifications are protected by the RTNL, not the RCU.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Time Of Check To Time Of Use
Improper Locking
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Linux Kernel