CVE-2025-1290

A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure during an AF_VSOCK connect syscall can occur before a worker thread accesses it resulting in a dangling pointer and potential kernel code execution.
Configurations

No configuration.

History

17 Apr 2025, 14:15

Type Values Removed Values Added
CWE CWE-416
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

17 Apr 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-17 01:15

Updated : 2025-04-17 20:21


NVD link : CVE-2025-1290

Mitre link : CVE-2025-1290

CVE.ORG link : CVE-2025-1290


JSON object : View

Products Affected

No product.

CWE
CWE-416

Use After Free