{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-38416", "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "state": "PUBLISHED", "assignerShortName": "Linux", "dateReserved": "2025-04-16T04:51:24.014Z", "datePublished": "2025-07-25T14:00:17.849Z", "dateUpdated": "2026-08-05T12:01:43.897Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67", "shortName": "Linux", "dateUpdated": "2026-08-05T12:01:43.897Z" }, "descriptions": [ { "lang": "en", "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nNFC: nci: uart: Set tty->disc_data only in success path\n\nSetting tty->disc_data before opening the NCI device means we need to\nclean it up on error paths. This also opens some short window if device\nstarts sending data, even before NCIUARTSETDRIVER IOCTL succeeded\n(broken hardware?). Close the window by exposing tty->disc_data only on\nthe success path, when opening of the NCI device and try_module_get()\nsucceeds.\n\nThe code differs in error path in one aspect: tty->disc_data won't be\never assigned thus NULL-ified. This however should not be relevant\ndifference, because of \"tty->disc_data=NULL\" in nci_uart_tty_open()." } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH" }, "scenarios": [ { "lang": "en", "value": "AV:L - Triggering requires a local `NCIUARTSETDRIVER` ioctl on a tty fd whose line discipline was set to N_NCI, plus locally-injected tty receive data (e.g. via a pty master). No remote or adjacent-network actor can open the window on their own.\nAC:L - The attacker controls both sides of the race — one thread issues the ioctl on a pty slave while another writes to the pty master to drive `flush_to_ldisc` → `nci_uart_tty_receive()` — and the `nu->ops.open()` failure that frees the object is inducible through attacker-driven memory pressure, so it can be retried until it lands.\nPR:L - `nci_uart_tty_ioctl()` performs no capability check and `/dev/ptmx` is world-accessible; on affected systems the nci_uart/nfcmrvl_uart modules are already resident, so the `capable(CAP_SYS_MODULE)` ldisc-autoload gate is not reached and a plain unprivileged user suffices.\nUI:N - The attacking process performs every step itself — opening the pty, setting the line discipline, issuing the ioctl and feeding the data. No victim action is involved.\nS:U - The use-after-free corrupts kernel heap state within the same kernel security authority; there is no VM, IOMMU, or sandbox boundary crossed.\nC:H - The freed `struct nci_uart` is reused while `nci_uart_default_recv_buf()` still dereferences `nu->ndev`, `nu->rx_skb`, and `nu->tty`, so a heap-sprayed replacement yields controlled kernel-memory reads and disclosure of adjacent slab contents.\nI:H - The stale object contains the `nu->ops` function-pointer table (`ops.recv`, `ops.tx_start`) and a `work_struct`, giving an attacker who reclaims the slab a controlled indirect call and skb-pointer writes — sufficient for control-flow hijack and privilege escalation.\nA:H - Even without successful exploitation the use-after-free dereferences and the `schedule_work()` on freed memory reliably produce a kernel oops or panic, and the race can be retried indefinitely." } ] } ], "affected": [ { "product": "Linux", "vendor": "Linux", "defaultStatus": "unaffected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/nfc/nci/uart.c" ], "versions": [ { "version": "9961127d4bce6325e9a0b0fb105e0c85a6c62cb7", "lessThan": "a514fca2b8e95838a3ba600f31a18fa60b76d893", "status": "affected", "versionType": "git" }, { "version": "9961127d4bce6325e9a0b0fb105e0c85a6c62cb7", "lessThan": "000bfbc6bc334a93fffca8f5aa9583e7b6356cb5", "status": "affected", "versionType": "git" }, { "version": "9961127d4bce6325e9a0b0fb105e0c85a6c62cb7", "lessThan": "ac6992f72bd8e22679c1e147ac214de6a7093c23", "status": "affected", "versionType": "git" }, { "version": "9961127d4bce6325e9a0b0fb105e0c85a6c62cb7", "lessThan": "dc7722619a9c307e9938d735cf4a2210d3d48dcb", "status": "affected", "versionType": "git" }, { "version": "9961127d4bce6325e9a0b0fb105e0c85a6c62cb7", "lessThan": "a8acc7080ad55c5402a1b818b3008998247dda87", "status": "affected", "versionType": "git" }, { "version": "9961127d4bce6325e9a0b0fb105e0c85a6c62cb7", "lessThan": "55c3dbd8389636161090a2b2b6d2d709b9602e9c", "status": "affected", "versionType": "git" }, { "version": "9961127d4bce6325e9a0b0fb105e0c85a6c62cb7", "lessThan": "e9799db771b2d574d5bf0dfb3177485e5f40d4d6", "status": "affected", "versionType": "git" }, { "version": "9961127d4bce6325e9a0b0fb105e0c85a6c62cb7", "lessThan": "fc27ab48904ceb7e4792f0c400f1ef175edf16fe", "status": "affected", "versionType": "git" } ] }, { "product": "Linux", "vendor": "Linux", "defaultStatus": "affected", "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git", "programFiles": [ "net/nfc/nci/uart.c" ], "versions": [ { "version": "4.2", "status": "affected" }, { "version": "0", "lessThan": "4.2", "status": "unaffected", "versionType": "semver" }, { "version": "5.4.295", "lessThanOrEqual": "5.4.*", "status": "unaffected", "versionType": "semver" }, { "version": "5.10.239", "lessThanOrEqual": "5.10.*", "status": "unaffected", "versionType": "semver" }, { "version": "5.15.186", "lessThanOrEqual": "5.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.1.142", "lessThanOrEqual": "6.1.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.6.95", "lessThanOrEqual": "6.6.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.12.35", "lessThanOrEqual": "6.12.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.15.4", "lessThanOrEqual": "6.15.*", "status": "unaffected", "versionType": "semver" }, { "version": "6.16", "lessThanOrEqual": "*", "status": "unaffected", "versionType": "original_commit_for_fix" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.2", "versionEndExcluding": "5.4.295" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.2", "versionEndExcluding": "5.10.239" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.2", "versionEndExcluding": "5.15.186" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.2", "versionEndExcluding": "6.1.142" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.2", "versionEndExcluding": "6.6.95" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.2", "versionEndExcluding": "6.12.35" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.2", "versionEndExcluding": "6.15.4" }, { "vulnerable": true, "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*", "versionStartIncluding": "4.2", "versionEndExcluding": "6.16" } ] } ] } ], "references": [ { "url": "https://git.kernel.org/stable/c/a514fca2b8e95838a3ba600f31a18fa60b76d893" }, { "url": "https://git.kernel.org/stable/c/000bfbc6bc334a93fffca8f5aa9583e7b6356cb5" }, { "url": "https://git.kernel.org/stable/c/ac6992f72bd8e22679c1e147ac214de6a7093c23" }, { "url": "https://git.kernel.org/stable/c/dc7722619a9c307e9938d735cf4a2210d3d48dcb" }, { "url": "https://git.kernel.org/stable/c/a8acc7080ad55c5402a1b818b3008998247dda87" }, { "url": "https://git.kernel.org/stable/c/55c3dbd8389636161090a2b2b6d2d709b9602e9c" }, { "url": "https://git.kernel.org/stable/c/e9799db771b2d574d5bf0dfb3177485e5f40d4d6" }, { "url": "https://git.kernel.org/stable/c/fc27ab48904ceb7e4792f0c400f1ef175edf16fe" } ], "title": "NFC: nci: uart: Set tty->disc_data only in success path", "x_generator": { "engine": "bippy-1.2.0" } }, "adp": [ { "title": "CVE Program Container", "references": [ { "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html" }, { "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html" } ], "providerMetadata": { "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2025-11-03T17:37:47.815Z" } } ] } }