{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-37949", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2025-04-16T04:51:23.972Z", "datePublished": "2025-05-20T16:01:45.242Z", "dateUpdated": "2026-08-05T11:58:34.906Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T11:58:34.906Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nxenbus: Use kref to track req lifetime\n\nMarek reported seeing a NULL pointer fault in the xenbus_thread\ncallstack:\nBUG: kernel NULL pointer dereference, address: 0000000000000000\nRIP: e030:__wake_up_common+0x4c/0x180\nCall Trace:\n \n __wake_up_common_lock+0x82/0xd0\n process_msg+0x18e/0x2f0\n xenbus_thread+0x165/0x1c0\n\nprocess_msg+0x18e is req->cb(req). req->cb is set to xs_wake_up(), a\nthin wrapper around wake_up(), or xenbus_dev_queue_reply(). It seems\nlike it was xs_wake_up() in this case.\n\nIt seems like req may have woken up the xs_wait_for_reply(), which\nkfree()ed the req. When xenbus_thread resumes, it faults on the zero-ed\ndata.\n\nLinux Device Drivers 2nd edition states:\n\"Normally, a wake_up call can cause an immediate reschedule to happen,\nmeaning that other processes might run before wake_up returns.\"\n... which would match the behaviour observed.\n\nChange to keeping two krefs on each request. One for the caller, and\none for xenbus_thread. Each will kref_put() when finished, and the last\nwill free it.\n\nThis use of kref matches the description in\nDocumentation/core-api/kref.rst" } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - The race is between the in-guest `xenbus_thread` and a local task blocked in `read_reply()`; it is driven by local writes to the `/dev/xen/xenbus` (or `/proc/xen/xenbus`) character device or by local sysfs/kernel-initiated xenstore requests. No network protocol handling is involved, so this requires local access to the Xen guest or dom0.\nAC:L - The attacker controls both sides of the race — their own thread is the waiter that performs the `kfree()`, and they issue the requests that cause `xenbus_thread` to call `wake_up()` — so they can retry unbounded, pin the racing threads to separate CPUs, and add scheduler load to widen the window. The bug is known to fire spontaneously during ordinary operation, confirming no attacker-uncontrollable precondition.\nPR:L - There is no `capable()` or credential check anywhere on the vulnerable path — unlike `xenbus_dev_backend.c` which gates on `CAP_SYS_ADMIN`, `xen_xenbus_fops` has none, so any user granted the xenbus device node can drive `XS_WATCH`/`XS_UNWATCH` into `xs_talkv()`; the world-readable `/sys/hypervisor/uuid` (mode 0444) also reaches `xenbus_read()` → `xs_talkv()`. A basic unprivileged local account suffices in realistic Xen deployments.\nUI:N - The attacker triggers the race entirely from their own thread pair by issuing xenstore requests and waiting for replies; no victim action, mount, or file open is required.\nS:U - The freed `xb_req_data` and the resulting corruption both live in the same kernel's slab, so the impact stays within the compromised guest's (or dom0's) security authority. No hypervisor, IOMMU, or VM boundary is crossed by the memory corruption itself.\nC:H - The use-after-free lets the attacker reallocate the freed `xb_req_data` with sprayed content that `__wake_up_common` then reads as a `wait_queue_entry` list, and the corrupted-object primitive is readily leveraged into arbitrary kernel memory disclosure. The object comes from a generic `kmalloc-128`/`kmalloc-192` cache shared with attacker-controllable allocations.\nI:H - `__wake_up_common` performs an indirect call `curr->func(curr, ...)` through a pointer read from the freed object, and `spin_unlock_irqrestore()` writes into the freed slot after reallocation — giving both control-flow hijack and a targeted write primitive, i.e. full kernel privilege escalation potential.\nA:H - The reported real-world symptom is a kernel NULL pointer dereference and oops in `__wake_up_common` from `xenbus_thread`, killing the xenstore transport thread and panicking the kernel. Any unsuccessful exploitation attempt likewise crashes the guest or dom0." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/xen/xenbus/xenbus.h", "drivers/xen/xenbus/xenbus_comms.c", "drivers/xen/xenbus/xenbus_dev_frontend.c", "drivers/xen/xenbus/xenbus_xs.c" ], "versions": [ { "version": "fd8aa9095a95c02dcc35540a263267c29b8fda9d", "lessThan": "0e94a246bb6d9538010b6c02d2b1d4717a97b2e5", "status": "affected", "versionType": "git" }, { "version": "fd8aa9095a95c02dcc35540a263267c29b8fda9d", "lessThan": "f1bcac367bc95631afbb918348f30dec887d0e1b", "status": "affected", "versionType": "git" }, { "version": "fd8aa9095a95c02dcc35540a263267c29b8fda9d", "lessThan": "4d260a5558df4650eb87bc41b2c9ac2d6b2ba447", "status": "affected", "versionType": "git" }, { "version": "fd8aa9095a95c02dcc35540a263267c29b8fda9d", "lessThan": "8b02f85e84dc6f7c150cef40ddb69af5a25659e5", "status": "affected", "versionType": "git" }, { "version": "fd8aa9095a95c02dcc35540a263267c29b8fda9d", "lessThan": "cbfaf46b88a4c01b64c4186cdccd766c19ae644c", "status": "affected", "versionType": "git" }, { "version": "fd8aa9095a95c02dcc35540a263267c29b8fda9d", "lessThan": "8e9c8a0393b5f85f1820c565ab8105660f4e8f92", "status": "affected", "versionType": "git" }, { "version": "fd8aa9095a95c02dcc35540a263267c29b8fda9d", "lessThan": "2466b0f66795c3c426cacc8998499f38031dbb59", "status": "affected", "versionType": "git" }, { "version": "fd8aa9095a95c02dcc35540a263267c29b8fda9d", "lessThan": "1f0304dfd9d217c2f8b04a9ef4b3258a66eedd27", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "drivers/xen/xenbus/xenbus.h", "drivers/xen/xenbus/xenbus_comms.c", "drivers/xen/xenbus/xenbus_dev_frontend.c", "drivers/xen/xenbus/xenbus_xs.c" ], "versions": [ { "version": "4.11", "status": "affected" }, { "version": "0", "lessThan": "4.11", "status": "unaffected", "versionType": "semver" }, { "version": "5.4.294", "lessThanOrEqual": "5.4.*", "status": "unaffected", "versionType": "semver" }, { "version": "5.10.238", "lessThanOrEqual": "5.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.183", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.139", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.91", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.29", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.14.7", "lessThanOrEqual": "6.14.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.15", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.11", "versionEndExcluding": "5.4.294" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.11", "versionEndExcluding": "5.10.238" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.11", "versionEndExcluding": "5.15.183" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.11", "versionEndExcluding": "6.1.139" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.11", "versionEndExcluding": "6.6.91" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.11", "versionEndExcluding": "6.12.29" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.11", "versionEndExcluding": "6.14.7" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.11", "versionEndExcluding": "6.15" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/0e94a246bb6d9538010b6c02d2b1d4717a97b2e5" }, { "url": "https://git.kernel.org/stable/c/f1bcac367bc95631afbb918348f30dec887d0e1b" }, { "url": "https://git.kernel.org/stable/c/4d260a5558df4650eb87bc41b2c9ac2d6b2ba447" }, { "url": "https://git.kernel.org/stable/c/8b02f85e84dc6f7c150cef40ddb69af5a25659e5" }, { "url": "https://git.kernel.org/stable/c/cbfaf46b88a4c01b64c4186cdccd766c19ae644c" }, { "url": "https://git.kernel.org/stable/c/8e9c8a0393b5f85f1820c565ab8105660f4e8f92" }, { "url": "https://git.kernel.org/stable/c/2466b0f66795c3c426cacc8998499f38031dbb59" }, { "url": "https://git.kernel.org/stable/c/1f0304dfd9d217c2f8b04a9ef4b3258a66eedd27" } ], "title": "xenbus: Use kref to track req lifetime", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "title": "CVE Program Container", "references": [ { "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html" }, { "url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00010.html" } ], "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2025-11-03T19:57:40.135Z" } } ] } }