EN

Tracker / CVE-2025-38416

CVE-2025-38416

Alta 7.8

In the Linux kernel, the following vulnerability has been resolved: NFC: nci: uart: Set tty->disc_data only in success path Setting tty->disc_data before opening the NCI device means we need to clean it up on error paths. This also opens some short window if device starts sending data, even before NCIUARTSETDRIVER IOCTL succeeded (broken hardware?). Close the window by exposing tty->disc_data only on the success path, when opening of the NCI device and try_module_get() succeeds. The code differs in error path in one aspect: tty->disc_data won't be ever assigned thus NULL-ified. This however should not be relevant difference, because of "tty->disc_data=NULL" in nci_uart_tty_open().

Prodotti e versioni affette

debian debian_linux
linux linux_kernel
linux linux_kernel · 4.2 → 5.4.295
linux linux_kernel · 5.11 → 5.15.186
linux linux_kernel · 5.16 → 6.1.142
linux linux_kernel · 5.5 → 5.10.239
linux linux_kernel · 6.13 → 6.15.4
linux linux_kernel · 6.2 → 6.6.95
linux linux_kernel · 6.7 → 6.12.35

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti