vulnerability
Ubuntu: (Multiple Advisories) (CVE-2025-21638): Linux kernel vulnerabilities
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
5 | (AV:L/AC:L/Au:S/C:N/I:N/A:C) | 2025-01-19 | 2025-03-28 | 2025-04-29 |
Description
In the Linux kernel, the following vulnerability has been resolved:
sctp: sysctl: auth_enable: avoid using current->nsproxy
As mentioned in a previous commit of this series, using the 'net'
structure via 'current' is not recommended for different reasons:
- Inconsistency: getting info from the reader's/writer's netns vs only
from the opener's netns.
- current->nsproxy can be NULL in some cases, resulting in an 'Oops'
(null-ptr-deref), e.g. when the current task is exiting, as spotted by
syzbot [1] using acct(2).
The 'net' structure can be obtained from the table->data using
container_of().
Note that table->data could also be used directly, but that would
increase the size of this fix, while 'sctp.ctl_sock' still needs to be
retrieved from 'net' structure.
Solution(s)
References
- CVE-2025-21638
- https://attackerkb.com/topics/CVE-2025-21638
- UBUNTU-USN-7379-1
- UBUNTU-USN-7379-2
- UBUNTU-USN-7380-1
- UBUNTU-USN-7381-1
- UBUNTU-USN-7382-1
- UBUNTU-USN-7387-1
- UBUNTU-USN-7387-2
- UBUNTU-USN-7387-3
- UBUNTU-USN-7388-1
- UBUNTU-USN-7389-1
- UBUNTU-USN-7390-1
- UBUNTU-USN-7391-1
- UBUNTU-USN-7392-1
- UBUNTU-USN-7392-2
- UBUNTU-USN-7392-3
- UBUNTU-USN-7392-4
- UBUNTU-USN-7393-1
- UBUNTU-USN-7401-1
- UBUNTU-USN-7407-1
- UBUNTU-USN-7413-1
- UBUNTU-USN-7421-1
- UBUNTU-USN-7458-1
- UBUNTU-USN-7459-1
- UBUNTU-USN-7459-2
- UBUNTU-USN-7463-1
- URL-https://git.kernel.org/linus/15649fd5415eda664ef35780c2013adeb5d9c695
- URL-https://git.kernel.org/stable/c/15649fd5415eda664ef35780c2013adeb5d9c695
- URL-https://git.kernel.org/stable/c/1b67030d39f2b00f94ac1f0af11ba6657589e4d3
- URL-https://git.kernel.org/stable/c/7ec30c54f339c640aa7e49d7e9f7bbed6bd42bf6
- URL-https://git.kernel.org/stable/c/c184bc621e3cef03ac9ba81a50dda2dae6a21d36
- URL-https://ubuntu.com/security/notices/USN-7379-1
- URL-https://ubuntu.com/security/notices/USN-7380-1
- URL-https://ubuntu.com/security/notices/USN-7381-1
- URL-https://ubuntu.com/security/notices/USN-7382-1
- URL-https://ubuntu.com/security/notices/USN-7387-1
- URL-https://ubuntu.com/security/notices/USN-7388-1
- URL-https://www.cve.org/CVERecord?id=CVE-2025-21638

Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.