CVE-2025-23155 (GCVE-0-2025-23155)
Vulnerability from cvelistv5
Published
2025-05-01 12:55
Modified
2026-08-05 11:57
Summary
In the Linux kernel, the following vulnerability has been resolved: net: stmmac: Fix accessing freed irq affinity_hint In stmmac_request_irq_multi_msi(), a pointer to the stack variable cpu_mask is passed to irq_set_affinity_hint(). This value is stored in irq_desc->affinity_hint, but once stmmac_request_irq_multi_msi() returns, the pointer becomes dangling. The affinity_hint is exposed via procfs with S_IRUGO permissions, allowing any unprivileged process to read it. Accessing this stale pointer can lead to: - a kernel oops or panic if the referenced memory has been released and unmapped, or - leakage of kernel data into userspace if the memory is re-used for other purposes. All platforms that use stmmac with PCI MSI (Intel, Loongson, etc) are affected.
Impacted products
Vendor Product Version
Linux Linux Version: 8deec94c6040bb4a767f6e9456a0a44c7f2e713e
Version: 8deec94c6040bb4a767f6e9456a0a44c7f2e713e
Version: 8deec94c6040bb4a767f6e9456a0a44c7f2e713e
Version: 8deec94c6040bb4a767f6e9456a0a44c7f2e713e
Version: 8deec94c6040bb4a767f6e9456a0a44c7f2e713e
Version: 8deec94c6040bb4a767f6e9456a0a44c7f2e713e
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/stmicro/stmmac/stmmac_main.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "2fbf67ddb8a0d0efc00d2df496a9843ec318d48b",
              "status": "affected",
              "version": "8deec94c6040bb4a767f6e9456a0a44c7f2e713e",
              "versionType": "git"
            },
            {
              "lessThan": "960dab23f6d405740c537d095f90a4ee9ddd9285",
              "status": "affected",
              "version": "8deec94c6040bb4a767f6e9456a0a44c7f2e713e",
              "versionType": "git"
            },
            {
              "lessThan": "442312c2a90d60c7a5197246583fa91d9e579985",
              "status": "affected",
              "version": "8deec94c6040bb4a767f6e9456a0a44c7f2e713e",
              "versionType": "git"
            },
            {
              "lessThan": "e148266e104fce396ad624079a6812ac3a9982ef",
              "status": "affected",
              "version": "8deec94c6040bb4a767f6e9456a0a44c7f2e713e",
              "versionType": "git"
            },
            {
              "lessThan": "9e51a6a44e2c4de780a26e8fe110d708e806a8cd",
              "status": "affected",
              "version": "8deec94c6040bb4a767f6e9456a0a44c7f2e713e",
              "versionType": "git"
            },
            {
              "lessThan": "c60d101a226f18e9a8f01bb4c6ca2b47dfcb15ef",
              "status": "affected",
              "version": "8deec94c6040bb4a767f6e9456a0a44c7f2e713e",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/net/ethernet/stmicro/stmmac/stmmac_main.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.13"
            },
            {
              "lessThan": "5.13",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.164",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.117",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.36",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.13.*",
              "status": "unaffected",
              "version": "6.13.12",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.14.*",
              "status": "unaffected",
              "version": "6.14.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "6.15",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.164",
                  "versionStartIncluding": "5.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.117",
                  "versionStartIncluding": "5.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.36",
                  "versionStartIncluding": "5.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.13.12",
                  "versionStartIncluding": "5.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.14.3",
                  "versionStartIncluding": "5.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.15",
                  "versionStartIncluding": "5.13",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: Fix accessing freed irq affinity_hint\n\nIn stmmac_request_irq_multi_msi(), a pointer to the stack variable\ncpu_mask is passed to irq_set_affinity_hint(). This value is stored in\nirq_desc-\u003eaffinity_hint, but once stmmac_request_irq_multi_msi()\nreturns, the pointer becomes dangling.\n\nThe affinity_hint is exposed via procfs with S_IRUGO permissions,\nallowing any unprivileged process to read it. Accessing this stale\npointer can lead to:\n\n- a kernel oops or panic if the referenced memory has been released and\n  unmapped, or\n- leakage of kernel data into userspace if the memory is re-used for\n  other purposes.\n\nAll platforms that use stmmac with PCI MSI (Intel, Loongson, etc) are\naffected."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is triggered by reading the local procfs file /proc/irq/\u003cN\u003e/affinity_hint, which requires local access to the system. Nothing in the dangling-pointer dereference path is reachable from network traffic.\nAC:L - A single `cat /proc/irq/N/affinity_hint` deterministically dereferences the stale stack pointer on any affected machine whose stmmac interface is up, and the read can be repeated at will. There is no race to win and no memory layout the attacker must guess.\nPR:L - The affinity_hint proc entry is created with S_IRUGO (0444), so any unprivileged local user or containerized process with /proc mounted can read it. The dangling pointer itself is installed by normal boot/ifup, requiring no privilege from the attacker.\nUI:N - The attacker reads the procfs file directly; no victim action is required, since the interface is already up as part of normal system operation.\nS:U - The stale pointer dereference and its consequences are entirely within the kernel\u0027s own security authority, with no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - This is a use-after-free read of a freed/reused kernel stack, and the contents are copied straight out to unprivileged userspace, repeatably. On the multi-core Intel and Loongson platforms that enable stmmac multi-MSI, each read discloses a full stale kernel stack word, sufficient to leak kernel pointers and defeat KASLR.\nI:N - desc-\u003eaffinity_hint is only ever stored, read, and NULLed \u2014 nothing writes through the stale pointer and it is never used as a function pointer, so the attacker gains no ability to modify kernel state.\nA:H - If the caller\u0027s VMAP_STACK kernel stack has been freed and its vmalloc range unmapped, the dereference faults inside raw_spin_lock_irqsave(\u0026desc-\u003elock) with interrupts disabled, producing an oops/panic and leaving the IRQ descriptor lock permanently held."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T11:57:06.134Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/2fbf67ddb8a0d0efc00d2df496a9843ec318d48b"
        },
        {
          "url": "https://git.kernel.org/stable/c/960dab23f6d405740c537d095f90a4ee9ddd9285"
        },
        {
          "url": "https://git.kernel.org/stable/c/442312c2a90d60c7a5197246583fa91d9e579985"
        },
        {
          "url": "https://git.kernel.org/stable/c/e148266e104fce396ad624079a6812ac3a9982ef"
        },
        {
          "url": "https://git.kernel.org/stable/c/9e51a6a44e2c4de780a26e8fe110d708e806a8cd"
        },
        {
          "url": "https://git.kernel.org/stable/c/c60d101a226f18e9a8f01bb4c6ca2b47dfcb15ef"
        }
      ],
      "title": "net: stmmac: Fix accessing freed irq affinity_hint",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2025-23155",
    "datePublished": "2025-05-01T12:55:41.607Z",
    "dateReserved": "2025-01-11T14:28:41.514Z",
    "dateUpdated": "2026-08-05T11:57:06.134Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…