{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-23155", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2025-01-11T14:28:41.514Z", "datePublished": "2025-05-01T12:55:41.607Z", "dateUpdated": "2026-08-05T11:57:06.134Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:57:06.134Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: stmmac: Fix accessing freed irq affinity_hint\n\nIn stmmac_request_irq_multi_msi(), a pointer to the stack variable\ncpu_mask is passed to irq_set_affinity_hint(). This value is stored in\nirq_desc->affinity_hint, but once stmmac_request_irq_multi_msi()\nreturns, the pointer becomes dangling.\n\nThe affinity_hint is exposed via procfs with S_IRUGO permissions,\nallowing any unprivileged process to read it. Accessing this stale\npointer can lead to:\n\n- a kernel oops or panic if the referenced memory has been released and\n unmapped, or\n- leakage of kernel data into userspace if the memory is re-used for\n other purposes.\n\nAll platforms that use stmmac with PCI MSI (Intel, Loongson, etc) are\naffected." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "baseScore": 7.1, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The vulnerability is triggered by reading the local procfs file /proc/irq//affinity_hint, which requires local access to the system. Nothing in the dangling-pointer dereference path is reachable from network traffic.\nAC:L - A single `cat /proc/irq/N/affinity_hint` deterministically dereferences the stale stack pointer on any affected machine whose stmmac interface is up, and the read can be repeated at will. There is no race to win and no memory layout the attacker must guess.\nPR:L - The affinity_hint proc entry is created with S_IRUGO (0444), so any unprivileged local user or containerized process with /proc mounted can read it. The dangling pointer itself is installed by normal boot/ifup, requiring no privilege from the attacker.\nUI:N - The attacker reads the procfs file directly; no victim action is required, since the interface is already up as part of normal system operation.\nS:U - The stale pointer dereference and its consequences are entirely within the kernel's own security authority, with no crossing of a VM, IOMMU, or sandbox boundary.\nC:H - This is a use-after-free read of a freed/reused kernel stack, and the contents are copied straight out to unprivileged userspace, repeatably. On the multi-core Intel and Loongson platforms that enable stmmac multi-MSI, each read discloses a full stale kernel stack word, sufficient to leak kernel pointers and defeat KASLR.\nI:N - desc->affinity_hint is only ever stored, read, and NULLed — nothing writes through the stale pointer and it is never used as a function pointer, so the attacker gains no ability to modify kernel state.\nA:H - If the caller's VMAP_STACK kernel stack has been freed and its vmalloc range unmapped, the dereference faults inside raw_spin_lock_irqsave(&desc->lock) with interrupts disabled, producing an oops/panic and leaving the IRQ descriptor lock permanently held." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/net/ethernet/stmicro/stmmac/stmmac_main.c" ], "versions": [ { "version": "8deec94c6040bb4a767f6e9456a0a44c7f2e713e", "lessThan": "2fbf67ddb8a0d0efc00d2df496a9843ec318d48b", "status": "affected", "versionType": "git" }, { "version": "8deec94c6040bb4a767f6e9456a0a44c7f2e713e", "lessThan": "960dab23f6d405740c537d095f90a4ee9ddd9285", "status": "affected", "versionType": "git" }, { "version": "8deec94c6040bb4a767f6e9456a0a44c7f2e713e", "lessThan": "442312c2a90d60c7a5197246583fa91d9e579985", "status": "affected", "versionType": "git" }, { "version": "8deec94c6040bb4a767f6e9456a0a44c7f2e713e", "lessThan": "e148266e104fce396ad624079a6812ac3a9982ef", "status": "affected", "versionType": "git" }, { "version": "8deec94c6040bb4a767f6e9456a0a44c7f2e713e", "lessThan": "9e51a6a44e2c4de780a26e8fe110d708e806a8cd", "status": "affected", "versionType": "git" }, { "version": "8deec94c6040bb4a767f6e9456a0a44c7f2e713e", "lessThan": "c60d101a226f18e9a8f01bb4c6ca2b47dfcb15ef", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/net/ethernet/stmicro/stmmac/stmmac_main.c" ], "versions": [ { "version": "5.13", "status": "affected" }, { "version": "0", "lessThan": "5.13", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.164", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.117", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.36", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.13.12", "lessThanOrEqual": "6.13.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.14.3", "lessThanOrEqual": "6.14.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.15", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.13", "versionEndExcluding": "6.1.164" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.13", "versionEndExcluding": "6.6.117" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.13", "versionEndExcluding": "6.12.36" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.13", "versionEndExcluding": "6.13.12" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.13", "versionEndExcluding": "6.14.3" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "5.13", "versionEndExcluding": "6.15" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/2fbf67ddb8a0d0efc00d2df496a9843ec318d48b" }, { "url": "https://git.kernel.org/stable/c/960dab23f6d405740c537d095f90a4ee9ddd9285" }, { "url": "https://git.kernel.org/stable/c/442312c2a90d60c7a5197246583fa91d9e579985" }, { "url": "https://git.kernel.org/stable/c/e148266e104fce396ad624079a6812ac3a9982ef" }, { "url": "https://git.kernel.org/stable/c/9e51a6a44e2c4de780a26e8fe110d708e806a8cd" }, { "url": "https://git.kernel.org/stable/c/c60d101a226f18e9a8f01bb4c6ca2b47dfcb15ef" } ], "title": "net: stmmac: Fix accessing freed irq affinity_hint", "x_generator": { "engine": "bippy-1.2.0" } } } }