Description
In the Linux kernel, the following vulnerability has been resolved: vsock: Fix transport_* TOCTOU Transport assignment may race with module unload. Protect new_transport from becoming a stale pointer. This also takes care of an insecure call in vsock_use_local_transport(); add a lockdep assert. BUG: unable to handle page fault for address: fffffbfff8056000 Oops: Oops: 0000 [#1] SMP KASAN RIP: 0010:vsock_assign_transport+0x366/0x600 Call Trace: vsock_connect+0x59c/0xc40 __sys_connect+0xe8/0x100 __x64_sys_connect+0x6e/0xc0 do_syscall_64+0x92/0x1c0 entry_SYSCALL_64_after_hwframe+0x4b/0x53
Product status
c0cfa2d8a788fcf45df5bf4070ab2474c88d543a (git) before 8667e8d0eb46bc54fdae30ba2f4786407d3d88eb
c0cfa2d8a788fcf45df5bf4070ab2474c88d543a (git) before 36a439049b34cca0b3661276049b84a1f76cc21a
c0cfa2d8a788fcf45df5bf4070ab2474c88d543a (git) before 9ce53e744f18e73059d3124070e960f3aa9902bf
c0cfa2d8a788fcf45df5bf4070ab2474c88d543a (git) before 9d24bb6780282b0255b9929abe5e8f98007e2c6e
c0cfa2d8a788fcf45df5bf4070ab2474c88d543a (git) before ae2c712ba39c7007de63cb0c75b51ce1caaf1da5
c0cfa2d8a788fcf45df5bf4070ab2474c88d543a (git) before 7b73bddf54777fb62d4d8c7729d0affe6df04477
c0cfa2d8a788fcf45df5bf4070ab2474c88d543a (git) before 687aa0c5581b8d4aa87fd92973e4ee576b550cdf
5.5
Any version before 5.5
5.10.240 (semver)
5.15.189 (semver)
6.1.146 (semver)
6.6.99 (semver)
6.12.39 (semver)
6.15.7 (semver)
6.16 (original_commit_for_fix)
References
lists.debian.org/debian-lts-announce/2025/10/msg00008.html
lists.debian.org/debian-lts-announce/2025/10/msg00007.html
git.kernel.org/...c/8667e8d0eb46bc54fdae30ba2f4786407d3d88eb
git.kernel.org/...c/36a439049b34cca0b3661276049b84a1f76cc21a
git.kernel.org/...c/9ce53e744f18e73059d3124070e960f3aa9902bf
git.kernel.org/...c/9d24bb6780282b0255b9929abe5e8f98007e2c6e
git.kernel.org/...c/ae2c712ba39c7007de63cb0c75b51ce1caaf1da5
git.kernel.org/...c/7b73bddf54777fb62d4d8c7729d0affe6df04477
git.kernel.org/...c/687aa0c5581b8d4aa87fd92973e4ee576b550cdf