In the Linux kernel, the following vulnerability has been resolved:
can: bcm: add missing rcu read protection for procfs content
When the procfs content is generated for a bcm_op which is in the process
to be removed the procfs output might show unreliable data (UAF).
As the removal of bcm_op's is already implemented with rcu handling this
patch adds the missing rcu_read_lock() and makes sure the list entries
are properly removed under rcu protection.
Metrics
Affected Vendors & Products
References
History
Tue, 10 Jun 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 10 Jun 2025 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Sun, 08 Jun 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In the Linux kernel, the following vulnerability has been resolved: can: bcm: add missing rcu read protection for procfs content When the procfs content is generated for a bcm_op which is in the process to be removed the procfs output might show unreliable data (UAF). As the removal of bcm_op's is already implemented with rcu handling this patch adds the missing rcu_read_lock() and makes sure the list entries are properly removed under rcu protection. | |
| Title | can: bcm: add missing rcu read protection for procfs content | |
| References |
|
|
Status: PUBLISHED
Assigner: Linux
Published: 2025-06-08T10:34:55.808Z
Updated: 2025-06-08T10:34:55.808Z
Reserved: 2025-04-16T04:51:23.977Z
Link: CVE-2025-38003
No data.
Status : Awaiting Analysis
Published: 2025-06-08T11:15:20.990
Modified: 2025-06-09T12:15:47.880
Link: CVE-2025-38003