{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-21801",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2024-12-29T08:45:45.770Z",
        "datePublished": "2025-02-27T20:00:55.572Z",
        "dateUpdated": "2026-08-05T11:54:32.458Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T11:54:32.458Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ravb: Fix missing rtnl lock in suspend/resume path\n\nFix the suspend/resume path by ensuring the rtnl lock is held where\nrequired. Calls to ravb_open, ravb_close and wol operations must be\nperformed under the rtnl lock to prevent conflicts with ongoing ndo\noperations.\n\nWithout this fix, the following warning is triggered:\n[   39.032969] =============================\n[   39.032983] WARNING: suspicious RCU usage\n[   39.033019] -----------------------------\n[   39.033033] drivers/net/phy/phy_device.c:2004 suspicious\nrcu_dereference_protected() usage!\n...\n[   39.033597] stack backtrace:\n[   39.033613] CPU: 0 UID: 0 PID: 174 Comm: python3 Not tainted\n6.13.0-rc7-next-20250116-arm64-renesas-00002-g35245dfdc62c #7\n[   39.033623] Hardware name: Renesas SMARC EVK version 2 based on\nr9a08g045s33 (DT)\n[   39.033628] Call trace:\n[   39.033633]  show_stack+0x14/0x1c (C)\n[   39.033652]  dump_stack_lvl+0xb4/0xc4\n[   39.033664]  dump_stack+0x14/0x1c\n[   39.033671]  lockdep_rcu_suspicious+0x16c/0x22c\n[   39.033682]  phy_detach+0x160/0x190\n[   39.033694]  phy_disconnect+0x40/0x54\n[   39.033703]  ravb_close+0x6c/0x1cc\n[   39.033714]  ravb_suspend+0x48/0x120\n[   39.033721]  dpm_run_callback+0x4c/0x14c\n[   39.033731]  device_suspend+0x11c/0x4dc\n[   39.033740]  dpm_suspend+0xdc/0x214\n[   39.033748]  dpm_suspend_start+0x48/0x60\n[   39.033758]  suspend_devices_and_enter+0x124/0x574\n[   39.033769]  pm_suspend+0x1ac/0x274\n[   39.033778]  state_store+0x88/0x124\n[   39.033788]  kobj_attr_store+0x14/0x24\n[   39.033798]  sysfs_kf_write+0x48/0x6c\n[   39.033808]  kernfs_fop_write_iter+0x118/0x1a8\n[   39.033817]  vfs_write+0x27c/0x378\n[   39.033825]  ksys_write+0x64/0xf4\n[   39.033833]  __arm64_sys_write+0x18/0x20\n[   39.033841]  invoke_syscall+0x44/0x104\n[   39.033852]  el0_svc_common.constprop.0+0xb4/0xd4\n[   39.033862]  do_el0_svc+0x18/0x20\n[   39.033870]  el0_svc+0x3c/0xf0\n[   39.033880]  el0t_64_sync_handler+0xc0/0xc4\n[   39.033888]  el0t_64_sync+0x154/0x158\n[   39.041274] ravb 11c30000.ethernet eth0: Link is Down"
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - The vulnerable code is a platform Ethernet driver's PM callback pair reached only through local activity — a suspend/resume transition plus a concurrent local rtnl-protected operation (ethtool ioctl, netlink, or an internally scheduled work item). No remote peer can reach or drive the unlocked window.\nAC:L - The attacker influences both sides: suspend/resume cycles are continuously and automatically driven on these Renesas embedded/automotive targets (and requestable by an unprivileged local session on general-purpose systems), while unprivileged ethtool/ioctl calls and interface traffic supply the concurrent rtnl-side operation, and the attempt can be repeated indefinitely until it lands.\nPR:L - An unprivileged local user suffices — `ETHTOOL_GSET`/`GLINKSETTINGS`/`GSTATS` are explicitly exempt from any capability check yet still run under `rtnl_lock()`, and generating the traffic that arms `ravb_tx_timeout_work()` needs only an ordinary socket; no root or `CAP_NET_ADMIN` is required.\nUI:N - System suspend/resume is triggered automatically by autosleep, idle timeouts, or RTC wakeups on the affected embedded and automotive platforms, so no victim action is needed for the window to open.\nS:U - The corruption is confined to kernel heap and DMA-coherent memory managed by the same kernel security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - The unlocked teardown frees the `phy_device` and the descriptor rings while concurrent rtnl holders still hold pointers to them, and use-after-free of these objects lets an attacker who reclaims the freed slabs read back kernel memory contents through the surviving accessors.\nI:H - Concurrent `ravb_ring_free()` from suspend and `ravb_tx_timeout_work()` double-frees DMA-coherent rings, page-pool objects, and kmalloc'd arrays, and the DMAC can remain programmed to write into freed pages — heap corruption plus a device-driven write primitive suitable for control-flow hijacking.\nA:H - The race reliably produces kernel crashes — double `dma_free_coherent`/`page_pool_destroy`, use-after-free oopses on the detached PHY, and external aborts from MMIO access to an AVB block whose reset is asserted and clocks gated — taking down the system's primary network interface and the machine itself."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/net/ethernet/renesas/ravb_main.c"
                    ],
                    "versions": [
                        {
                            "version": "0184165b2f42c4b032da9dd11546bfbaeb5afd4e",
                            "lessThan": "0296981941cf291edfbc318d3255a93439f368e4",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0184165b2f42c4b032da9dd11546bfbaeb5afd4e",
                            "lessThan": "ad19522c007bb24ed874468f8baa1503c4662cf4",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "0184165b2f42c4b032da9dd11546bfbaeb5afd4e",
                            "lessThan": "2c2ebb2b49573e5f8726112ad06b1dffc3c9ea03",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/net/ethernet/renesas/ravb_main.c"
                    ],
                    "versions": [
                        {
                            "version": "4.9",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "4.9",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.13",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.13.2",
                            "lessThanOrEqual": "6.13.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.14",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.9",
                                    "versionEndExcluding": "6.12.13"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.9",
                                    "versionEndExcluding": "6.13.2"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.9",
                                    "versionEndExcluding": "6.14"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/0296981941cf291edfbc318d3255a93439f368e4"
                },
                {
                    "url": "https://git.kernel.org/stable/c/ad19522c007bb24ed874468f8baa1503c4662cf4"
                },
                {
                    "url": "https://git.kernel.org/stable/c/2c2ebb2b49573e5f8726112ad06b1dffc3c9ea03"
                }
            ],
            "title": "net: ravb: Fix missing rtnl lock in suspend/resume path",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}