{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-21792",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-12-29T08:45:45.767Z",
        "datePublished": "2025-02-27T02:18:29.653Z",
        "dateUpdated": "2026-08-05T11:54:29.234Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:54:29.234Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nax25: Fix refcount leak caused by setting SO_BINDTODEVICE sockopt\n\nIf an AX25 device is bound to a socket by setting the SO_BINDTODEVICE\nsocket option, a refcount leak will occur in ax25_release().\n\nCommit 9fd75b66b8f6 (\"ax25: Fix refcount leaks caused by ax25_cb_del()\")\nadded decrement of device refcounts in ax25_release(). In order for that\nto work correctly the refcounts must already be incremented when the\ndevice is bound to the socket. An AX25 device can be bound to a socket\nby either calling ax25_bind() or setting SO_BINDTODEVICE socket option.\nIn both cases the refcounts should be incremented, but in fact it is done\nonly in ax25_bind().\n\nThis bug leads to the following issue reported by Syzkaller:\n\n================================================================\nrefcount_t: decrement hit 0; leaking memory.\nWARNING: CPU: 1 PID: 5932 at lib/refcount.c:31 refcount_warn_saturate+0x1ed/0x210 lib/refcount.c:31\nModules linked in:\nCPU: 1 UID: 0 PID: 5932 Comm: syz-executor424 Not tainted 6.13.0-rc4-syzkaller-00110-g4099a71718b0 #0\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2~bpo12+1 04/01/2014\nRIP: 0010:refcount_warn_saturate+0x1ed/0x210 lib/refcount.c:31\nCall Trace:\n <TASK>\n __refcount_dec include/linux/refcount.h:336 [inline]\n refcount_dec include/linux/refcount.h:351 [inline]\n ref_tracker_free+0x710/0x820 lib/ref_tracker.c:236\n netdev_tracker_free include/linux/netdevice.h:4156 [inline]\n netdev_put include/linux/netdevice.h:4173 [inline]\n netdev_put include/linux/netdevice.h:4169 [inline]\n ax25_release+0x33f/0xa10 net/ax25/af_ax25.c:1069\n __sock_release+0xb0/0x270 net/socket.c:640\n sock_close+0x1c/0x30 net/socket.c:1408\n ...\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x250 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n ...\n </TASK>\n================================================================\n\nFix the implementation of ax25_setsockopt() by adding increment of\nrefcounts for the new device bound, and decrement of refcounts for\nthe old unbound device."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The bug is triggered entirely through local syscalls — `socket(AF_AX25, SOCK_DGRAM, 0)`, `setsockopt(SOL_AX25, SO_BINDTODEVICE, ...)`, and `close()`. No network packet or remote peer input is involved in reaching the faulty refcount path.\nAC:L - The underflow is fully deterministic — every socket bound via SO_BINDTODEVICE and then closed drops two references it never took, with no race to win and no memory layout the attacker cannot influence. The cycle can be repeated arbitrarily to drive `ax25_dev->refcount` to zero on demand and then groom the freed slab.\nPR:L - Creating an AF_AX25 SOCK_DGRAM socket and setting SO_BINDTODEVICE require no capabilities at all — the only `capable(CAP_NET_RAW)` check in `ax25_create()` guards SOCK_RAW. On any system with AX.25 already configured (packet-radio node, APRS igate, embedded radio gateway), an ordinary unprivileged user can trigger it.\nUI:N - The attacker performs the entire sequence in their own process; no victim action, mount, or file open is needed. Closing the socket is what fires the erroneous `netdev_put()`/`ax25_dev_put()`.\nS:U - The corrupted refcounts and freed objects (`struct ax25_dev`, `struct net_device`) live in the kernel, and exploitation yields kernel-level compromise within the same security authority. No VM, IOMMU, or sandbox boundary is crossed.\nC:H - The premature `kfree_rcu()` of `ax25_dev` leaves `dev->ax25_ptr` dangling and read by `ax25_rcv()`, `ax25_out.c`, and `ax25_ip_xmit()`, so reallocated slab contents are read back as `values[]`, `forward`, and `sysheader`. A use-after-free of this shape gives the attacker a path to disclose arbitrary kernel memory.\nI:H - After the underflow frees `ax25_dev`, the attacker can spray the slab and control `struct net_device *forward` (used as a transmit target by `ax25_fwd_dev()`), `sysheader`, and the DAMA `timer_list`, yielding write and control-flow-hijack primitives. The parallel `net_device` refcount underflow lets `unregister_netdevice()` free a netdev still in use.\nA:H - The immediate observable is a `refcount_warn_saturate` WARN followed by dereference of freed memory in the AX.25 receive and transmit paths, i.e. kernel oops/panic. Any unprivileged user can repeat the trigger to reliably crash the machine."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/ax25/af_ax25.c"
                    ],
                    "versions": [
                        {
                            "version": "9fd75b66b8f68498454d685dc4ba13192ae069b0",
                            "lessThan": "90056ece99966182dc0e367f3fd2afab46ada847",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "9fd75b66b8f68498454d685dc4ba13192ae069b0",
                            "lessThan": "94a0de224ed52eb2ecd4f4cb1b937b674c9fb955",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "9fd75b66b8f68498454d685dc4ba13192ae069b0",
                            "lessThan": "b58f7ca86a7b8e480c06e30c5163c5d2f4e24023",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "9fd75b66b8f68498454d685dc4ba13192ae069b0",
                            "lessThan": "470bda72fda0fcf54300466d70ce2de62f7835d2",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "9fd75b66b8f68498454d685dc4ba13192ae069b0",
                            "lessThan": "bca0902e61731a75fc4860c8720168d9f1bae3b6",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "c44a453ffe16eb08acdc6129ac4fa0192dbc0456",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "de55a1338e6a48ff1e41ea8db1432496fbe2a62b",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "9e1e088a57c23251f1cfe9601bbd90ade2ea73b9",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "b20a5ab0f5fb175750c6bafd4cf12daccf00c738",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "452ae92b99062d2f6a34324eaf705a3b7eac9f8b",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "534156dd4ed768e30a43de0036f45dca7c54818f",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "4.14.277",
                            "lessThan": "4.15",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "4.19.240",
                            "lessThan": "4.20",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.4.190",
                            "lessThan": "5.5",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.112",
                            "lessThan": "5.11",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.35",
                            "lessThan": "5.16",
                            "status": "affected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.17.2",
                            "lessThan": "5.18",
                            "status": "affected",
                            "versionType": "semver"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "net/ax25/af_ax25.c"
                    ],
                    "versions": [
                        {
                            "version": "5.18",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.18",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.129",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.79",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.16",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.13.4",
                            "lessThanOrEqual": "6.13.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.14",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.18",
                                    "versionEndExcluding": "6.1.129"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.18",
                                    "versionEndExcluding": "6.6.79"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.18",
                                    "versionEndExcluding": "6.12.16"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.18",
                                    "versionEndExcluding": "6.13.4"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.18",
                                    "versionEndExcluding": "6.14"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.14.277"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.19.240"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.4.190"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.10.112"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.15.35"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.17.2"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/90056ece99966182dc0e367f3fd2afab46ada847"
                },
                {
                    "url": "https://git.kernel.org/stable/c/94a0de224ed52eb2ecd4f4cb1b937b674c9fb955"
                },
                {
                    "url": "https://git.kernel.org/stable/c/b58f7ca86a7b8e480c06e30c5163c5d2f4e24023"
                },
                {
                    "url": "https://git.kernel.org/stable/c/470bda72fda0fcf54300466d70ce2de62f7835d2"
                },
                {
                    "url": "https://git.kernel.org/stable/c/bca0902e61731a75fc4860c8720168d9f1bae3b6"
                }
            ],
            "title": "ax25: Fix refcount leak caused by setting SO_BINDTODEVICE sockopt",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "cvssV3_1": {
                            "scope": "UNCHANGED",
                            "version": "3.1",
                            "baseScore": 5.5,
                            "attackVector": "LOCAL",
                            "baseSeverity": "MEDIUM",
                            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                            "integrityImpact": "NONE",
                            "userInteraction": "NONE",
                            "attackComplexity": "LOW",
                            "availabilityImpact": "HIGH",
                            "privilegesRequired": "LOW",
                            "confidentialityImpact": "NONE"
                        }
                    },
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "id": "CVE-2025-21792",
                                "role": "CISA Coordinator",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "version": "2.0.3",
                                "timestamp": "2025-10-01T19:29:51.044536Z"
                            }
                        }
                    }
                ],
                "problemTypes": [
                    {
                        "descriptions": [
                            {
                                "lang": "en",
                                "type": "CWE",
                                "description": "CWE-noinfo Not enough information"
                            }
                        ]
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-10-01T19:36:39.465Z"
                }
            },
            {
                "title": "CVE Program Container",
                "references": [
                    {
                        "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html"
                    }
                ],
                "providerMetadata": {
                    "orgId": "af854a3a-2127-422b-91ae-364da2661108",
                    "shortName": "CVE",
                    "dateUpdated": "2025-11-03T20:59:36.026Z"
                }
            }
        ]
    }
}