{"id":"DEBIAN-CVE-2025-21756","details":"In the Linux kernel, the following vulnerability has been resolved:  vsock: Keep the binding until socket destruction  Preserve sockets bindings; this includes both resulting from an explicit bind() and those implicitly bound through autobind during connect().  Prevents socket unbinding during a transport reassignment, which fixes a use-after-free:      1. vsock_create() (refcnt=1) calls vsock_insert_unbound() (refcnt=2)     2. transport-\u003erelease() calls vsock_remove_bound() without checking if        sk was bound and moved to bound list (refcnt=1)     3. vsock_bind() assumes sk is in unbound list and before        __vsock_insert_bound(vsock_bound_sockets()) calls        __vsock_remove_bound() which does:            list_del_init(&vsk-\u003ebound_table); // nop            sock_put(&vsk-\u003esk);               // refcnt=0  BUG: KASAN: slab-use-after-free in __vsock_bind+0x62e/0x730 Read of size 4 at addr ffff88816b46a74c by task a.out/2057  dump_stack_lvl+0x68/0x90  print_report+0x174/0x4f6  kasan_report+0xb9/0x190  __vsock_bind+0x62e/0x730  vsock_bind+0x97/0xe0  __sys_bind+0x154/0x1f0  __x64_sys_bind+0x6e/0xb0  do_syscall_64+0x93/0x1b0  entry_SYSCALL_64_after_hwframe+0x76/0x7e  Allocated by task 2057:  kasan_save_stack+0x1e/0x40  kasan_save_track+0x10/0x30  __kasan_slab_alloc+0x85/0x90  kmem_cache_alloc_noprof+0x131/0x450  sk_prot_alloc+0x5b/0x220  sk_alloc+0x2c/0x870  __vsock_create.constprop.0+0x2e/0xb60  vsock_create+0xe4/0x420  __sock_create+0x241/0x650  __sys_socket+0xf2/0x1a0  __x64_sys_socket+0x6e/0xb0  do_syscall_64+0x93/0x1b0  entry_SYSCALL_64_after_hwframe+0x76/0x7e  Freed by task 2057:  kasan_save_stack+0x1e/0x40  kasan_save_track+0x10/0x30  kasan_save_free_info+0x37/0x60  __kasan_slab_free+0x4b/0x70  kmem_cache_free+0x1a1/0x590  __sk_destruct+0x388/0x5a0  __vsock_bind+0x5e1/0x730  vsock_bind+0x97/0xe0  __sys_bind+0x154/0x1f0  __x64_sys_bind+0x6e/0xb0  do_syscall_64+0x93/0x1b0  entry_SYSCALL_64_after_hwframe+0x76/0x7e  refcount_t: addition on 0; use-after-free. WARNING: CPU: 7 PID: 2057 at lib/refcount.c:25 refcount_warn_saturate+0xce/0x150 RIP: 0010:refcount_warn_saturate+0xce/0x150  __vsock_bind+0x66d/0x730  vsock_bind+0x97/0xe0  __sys_bind+0x154/0x1f0  __x64_sys_bind+0x6e/0xb0  do_syscall_64+0x93/0x1b0  entry_SYSCALL_64_after_hwframe+0x76/0x7e  refcount_t: underflow; use-after-free. WARNING: CPU: 7 PID: 2057 at lib/refcount.c:28 refcount_warn_saturate+0xee/0x150 RIP: 0010:refcount_warn_saturate+0xee/0x150  vsock_remove_bound+0x187/0x1e0  __vsock_release+0x383/0x4a0  vsock_release+0x90/0x120  __sock_release+0xa3/0x250  sock_close+0x14/0x20  __fput+0x359/0xa80  task_work_run+0x107/0x1d0  do_exit+0x847/0x2560  do_group_exit+0xb8/0x250  __x64_sys_exit_group+0x3a/0x50  x64_sys_call+0xfec/0x14f0  do_syscall_64+0x93/0x1b0  entry_SYSCALL_64_after_hwframe+0x76/0x7e","modified":"2026-09-01T16:06:09.830318080Z","published":"2025-02-27T03:15:16.250Z","upstream":["CVE-2025-21756"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-21756"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.133-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21756.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.16-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21756.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.16-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21756.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}