« Volver al listado

CVE-2025-38727

Estado: ModificadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

netlink: avoid infinite retry looping in netlink_unicast()

netlink_attachskb() checks for the socket's read memory allocation constraints. Firstly, it has:

to check if the just increased rmem value fits into the socket's receive buffer. If not, it proceeds and tries to wait for the memory under:

The checks don't cover the case when skb->truesize + sk->sk_rmem_alloc is equal to sk->sk_rcvbuf. Thus the function neither successfully accepts these conditions, nor manages to reschedule the task - and is called in retry loop for indefinite time which is caught as:

Leer descripción completaMostrar menos

Restore the original behavior of the check which commit in Fixes accidentally missed when restructuring the code.

Found by Linux Verification Center (linuxtesting.org).

Detalles técnicos trazas, registros y código del informe original
  rmem < READ_ONCE(sk->sk_rcvbuf)

  rmem + skb->truesize > READ_ONCE(sk->sk_rcvbuf)

  rcu: INFO: rcu_sched self-detected stall on CPU
  rcu:     0-....: (25999 ticks this GP) idle=ef2/1/0x4000000000000000 softirq=262269/262269 fqs=6212
  (t=26000 jiffies g=230833 q=259957)
  NMI backtrace for cpu 0
  CPU: 0 PID: 22 Comm: kauditd Not tainted 5.10.240 #68
  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc42 04/01/2014
  Call Trace:
  <IRQ>
  dump_stack lib/dump_stack.c:120
  nmi_cpu_backtrace.cold lib/nmi_backtrace.c:105
  nmi_trigger_cpumask_backtrace lib/nmi_backtrace.c:62
  rcu_dump_cpu_stacks kernel/rcu/tree_stall.h:335
  rcu_sched_clock_irq.cold kernel/rcu/tree.c:2590
  update_process_times kernel/time/timer.c:1953
  tick_sched_handle kernel/time/tick-sched.c:227
  tick_sched_timer kernel/time/tick-sched.c:1399
  __hrtimer_run_queues kernel/time/hrtimer.c:1652
  hrtimer_interrupt kernel/time/hrtimer.c:1717
  __sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1113
  asm_call_irq_on_stack arch/x86/entry/entry_64.S:808
  </IRQ>

  netlink_attachskb net/netlink/af_netlink.c:1234
  netlink_unicast net/netlink/af_netlink.c:1349
  kauditd_send_queue kernel/audit.c:776
  kauditd_thread kernel/audit.c:897
  kthread kernel/kthread.c:328
  ret_from_fork arch/x86/entry/entry_64.S:304

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-38727",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "9da025150b7c14a8390fc06aea314c0a4011e82c",
              "lessThan": "47d49fd07f86d1f55ea1083287303d237e9e0922",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "c4ceaac5c5ba0b992ee1dc88e2a02421549e5c98",
              "lessThan": "6bee383ff83352a693d03efdf27cdd80742f71b2",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "fd69af06101090eaa60b3d216ae715f9c0a58e5b",
              "lessThan": "f324959ad47e62e3cadaffa65d3cff790fb48529",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "76602d8e13864524382b0687dc32cd8f19164d5a",
              "lessThan": "d42b71a34f6b8a2d5c53df81169b03b8d8b5cf4e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "55baecb9eb90238f60a8350660d6762046ebd3bd",
              "lessThan": "346c820ef5135cf062fa3473da955ef8c5fb6929",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "4b8e18af7bea92f8b7fb92d40aeae729209db250",
              "lessThan": "44ddd7b1ae0b7edb2c832eb16798c827a05e58f0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "cd7ff61bfffd7000143c42bbffb85eeb792466d6",
              "lessThan": "78fcd69d55c5f11d7694c547eca767a1cfd38ec4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ae8f160e7eb24240a2a79fc4c815c6a0d4ee16cc",
              "lessThan": "e8edc7de688791a337c068693f22e8d8b869df71",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "ae8f160e7eb24240a2a79fc4c815c6a0d4ee16cc",
              "lessThan": "759dfc7d04bab1b0b86113f1164dc1fec192b859",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.4.296",
              "lessThan": "5.4.297",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.10.240",
              "lessThan": "5.10.241",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.15.189",
              "lessThan": "5.15.190",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.1.146",
              "lessThan": "6.1.149",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.6.99",
              "lessThan": "6.6.103",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.39",
              "lessThan": "6.12.43",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.15.7",
              "lessThan": "6.15.11",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/netlink/af_netlink.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.4.297",
              "versionType": "semver",
              "lessThanOrEqual": "5.4.*"
            },
            {
              "status": "unaffected",
              "version": "5.10.241",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.190",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.149",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.103",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.43",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.15.11",
              "versionType": "semver",
              "lessThanOrEqual": "6.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.16.2",
              "versionType": "semver",
              "lessThanOrEqual": "6.16.*"
            },
            {
              "status": "unaffected",
              "version": "6.17",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/netlink/af_netlink.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
      "affectedData": [
        {
          "vendor": "Siemens",
          "product": "SIMATIC CN 4100",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "V5.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.5",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.6",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.5",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.6",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.5",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.6",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.5",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.6",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.5",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "vendor": "Siemens",
          "product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
          "versions": [
            {
              "status": "affected",
              "version": "V3.1.6",
              "lessThan": "*",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2025-09-04T16:15:42.713",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/346c820ef5135cf062fa3473da955ef8c5fb6929",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/44ddd7b1ae0b7edb2c832eb16798c827a05e58f0",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/47d49fd07f86d1f55ea1083287303d237e9e0922",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6bee383ff83352a693d03efdf27cdd80742f71b2",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/759dfc7d04bab1b0b86113f1164dc1fec192b859",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/78fcd69d55c5f11d7694c547eca767a1cfd38ec4",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d42b71a34f6b8a2d5c53df81169b03b8d8b5cf4e",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e8edc7de688791a337c068693f22e8d8b869df71",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f324959ad47e62e3cadaffa65d3cff790fb48529",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
      "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/html/ssa-032379.html",
      "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
      "source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-835"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetlink: avoid infinite retry looping in netlink_unicast()\n\nnetlink_attachskb() checks for the socket's read memory allocation\nconstraints. Firstly, it has:\n\n  rmem < READ_ONCE(sk->sk_rcvbuf)\n\nto check if the just increased rmem value fits into the socket's receive\nbuffer. If not, it proceeds and tries to wait for the memory under:\n\n  rmem + skb->truesize > READ_ONCE(sk->sk_rcvbuf)\n\nThe checks don't cover the case when skb->truesize + sk->sk_rmem_alloc is\nequal to sk->sk_rcvbuf. Thus the function neither successfully accepts\nthese conditions, nor manages to reschedule the task - and is called in\nretry loop for indefinite time which is caught as:\n\n  rcu: INFO: rcu_sched self-detected stall on CPU\n  rcu:     0-....: (25999 ticks this GP) idle=ef2/1/0x4000000000000000 softirq=262269/262269 fqs=6212\n  (t=26000 jiffies g=230833 q=259957)\n  NMI backtrace for cpu 0\n  CPU: 0 PID: 22 Comm: kauditd Not tainted 5.10.240 #68\n  Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-4.fc42 04/01/2014\n  Call Trace:\n  <IRQ>\n  dump_stack lib/dump_stack.c:120\n  nmi_cpu_backtrace.cold lib/nmi_backtrace.c:105\n  nmi_trigger_cpumask_backtrace lib/nmi_backtrace.c:62\n  rcu_dump_cpu_stacks kernel/rcu/tree_stall.h:335\n  rcu_sched_clock_irq.cold kernel/rcu/tree.c:2590\n  update_process_times kernel/time/timer.c:1953\n  tick_sched_handle kernel/time/tick-sched.c:227\n  tick_sched_timer kernel/time/tick-sched.c:1399\n  __hrtimer_run_queues kernel/time/hrtimer.c:1652\n  hrtimer_interrupt kernel/time/hrtimer.c:1717\n  __sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1113\n  asm_call_irq_on_stack arch/x86/entry/entry_64.S:808\n  </IRQ>\n\n  netlink_attachskb net/netlink/af_netlink.c:1234\n  netlink_unicast net/netlink/af_netlink.c:1349\n  kauditd_send_queue kernel/audit.c:776\n  kauditd_thread kernel/audit.c:897\n  kthread kernel/kthread.c:328\n  ret_from_fork arch/x86/entry/entry_64.S:304\n\nRestore the original behavior of the check which commit in Fixes\naccidentally missed when restructuring the code.\n\nFound by Linux Verification Center (linuxtesting.org)."
    }
  ],
  "lastModified": "2026-07-14T13:17:46.373",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81B2A3AB-7EDD-4A86-A6DE-578C92109750",
              "versionEndExcluding": "6.1.149",
              "versionStartIncluding": "6.1.146"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB7770EC-6722-4972-A31B-8A3FF8093654",
              "versionEndExcluding": "6.6.103",
              "versionStartIncluding": "6.6.99"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "66C90F36-657B-4AEE-9904-2AF95EA7920F",
              "versionEndExcluding": "6.12.43",
              "versionStartIncluding": "6.12.39"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B61C948D-1EE2-4D6F-AA21-5EB6E3C263F9",
              "versionEndExcluding": "6.15.11",
              "versionStartIncluding": "6.15.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D18D370-ABE4-48A4-A953-C7A2D7BE7210",
              "versionEndExcluding": "6.16.2",
              "versionStartIncluding": "6.16.1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:5.4.296:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0EAAD549-C67B-41DE-B9BC-9DD6C63698A2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:5.10.240:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A07714F-7EC7-40FD-BD62-410EE6619A10"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:5.15.189:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37B96E15-5206-4222-8214-8DCDF74FEC5C"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6238B17D-C12B-458F-A138-97039BFC4595"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3827F0D4-5FEE-4181-B267-5A45E7CA11FC"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.16:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A9C2DE5-43B8-4D73-BDB5-EA55C7671A52"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA6FEEC2-9F11-4643-8827-749718254FED"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}