A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure
during an AF_VSOCK connect syscall can occur before a worker thread accesses it resulting in a dangling pointer and potential kernel code execution.
References
Configurations
No configuration.
History
17 Apr 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-416 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
17 Apr 2025, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-17 01:15
Updated : 2025-04-17 20:21
NVD link : CVE-2025-1290
Mitre link : CVE-2025-1290
CVE.ORG link : CVE-2025-1290
JSON object : View
Products Affected
No product.
CWE
CWE-416
Use After Free