{"id":"DEBIAN-CVE-2025-38323","details":"In the Linux kernel, the following vulnerability has been resolved:  net: atm: add lec_mutex  syzbot found its way in net/atm/lec.c, and found an error path in lecd_attach() could leave a dangling pointer in dev_lec[].  Add a mutex to protect dev_lecp[] uses from lecd_attach(), lec_vcc_attach() and lec_mcast_attach().  Following patch will use this mutex for /proc/net/atm/lec.  BUG: KASAN: slab-use-after-free in lecd_attach net/atm/lec.c:751 [inline] BUG: KASAN: slab-use-after-free in lane_ioctl+0x2224/0x23e0 net/atm/lec.c:1008 Read of size 8 at addr ffff88807c7b8e68 by task syz.1.17/6142  CPU: 1 UID: 0 PID: 6142 Comm: syz.1.17 Not tainted 6.16.0-rc1-syzkaller-00239-g08215f5486ec #0 PREEMPT(full) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025 Call Trace:  \u003cTASK\u003e   __dump_stack lib/dump_stack.c:94 [inline]   dump_stack_lvl+0x116/0x1f0 lib/dump_stack.c:120   print_address_description mm/kasan/report.c:408 [inline]   print_report+0xcd/0x680 mm/kasan/report.c:521   kasan_report+0xe0/0x110 mm/kasan/report.c:634   lecd_attach net/atm/lec.c:751 [inline]   lane_ioctl+0x2224/0x23e0 net/atm/lec.c:1008   do_vcc_ioctl+0x12c/0x930 net/atm/ioctl.c:159   sock_do_ioctl+0x118/0x280 net/socket.c:1190   sock_ioctl+0x227/0x6b0 net/socket.c:1311   vfs_ioctl fs/ioctl.c:51 [inline]   __do_sys_ioctl fs/ioctl.c:907 [inline]   __se_sys_ioctl fs/ioctl.c:893 [inline]   __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:893   do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]   do_syscall_64+0xcd/0x4c0 arch/x86/entry/syscall_64.c:94  entry_SYSCALL_64_after_hwframe+0x77/0x7f  \u003c/TASK\u003e  Allocated by task 6132:   kasan_save_stack+0x33/0x60 mm/kasan/common.c:47   kasan_save_track+0x14/0x30 mm/kasan/common.c:68   poison_kmalloc_redzone mm/kasan/common.c:377 [inline]   __kasan_kmalloc+0xaa/0xb0 mm/kasan/common.c:394   kasan_kmalloc include/linux/kasan.h:260 [inline]   __do_kmalloc_node mm/slub.c:4328 [inline]   __kvmalloc_node_noprof+0x27b/0x620 mm/slub.c:5015   alloc_netdev_mqs+0xd2/0x1570 net/core/dev.c:11711   lecd_attach net/atm/lec.c:737 [inline]   lane_ioctl+0x17db/0x23e0 net/atm/lec.c:1008   do_vcc_ioctl+0x12c/0x930 net/atm/ioctl.c:159   sock_do_ioctl+0x118/0x280 net/socket.c:1190   sock_ioctl+0x227/0x6b0 net/socket.c:1311   vfs_ioctl fs/ioctl.c:51 [inline]   __do_sys_ioctl fs/ioctl.c:907 [inline]   __se_sys_ioctl fs/ioctl.c:893 [inline]   __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:893   do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]   do_syscall_64+0xcd/0x4c0 arch/x86/entry/syscall_64.c:94  entry_SYSCALL_64_after_hwframe+0x77/0x7f  Freed by task 6132:   kasan_save_stack+0x33/0x60 mm/kasan/common.c:47   kasan_save_track+0x14/0x30 mm/kasan/common.c:68   kasan_save_free_info+0x3b/0x60 mm/kasan/generic.c:576   poison_slab_object mm/kasan/common.c:247 [inline]   __kasan_slab_free+0x51/0x70 mm/kasan/common.c:264   kasan_slab_free include/linux/kasan.h:233 [inline]   slab_free_hook mm/slub.c:2381 [inline]   slab_free mm/slub.c:4643 [inline]   kfree+0x2b4/0x4d0 mm/slub.c:4842   free_netdev+0x6c5/0x910 net/core/dev.c:11892   lecd_attach net/atm/lec.c:744 [inline]   lane_ioctl+0x1ce8/0x23e0 net/atm/lec.c:1008   do_vcc_ioctl+0x12c/0x930 net/atm/ioctl.c:159   sock_do_ioctl+0x118/0x280 net/socket.c:1190   sock_ioctl+0x227/0x6b0 net/socket.c:1311   vfs_ioctl fs/ioctl.c:51 [inline]   __do_sys_ioctl fs/ioctl.c:907 [inline]   __se_sys_ioctl fs/ioctl.c:893 [inline]   __x64_sys_ioctl+0x18e/0x210 fs/ioctl.c:893","modified":"2026-09-01T16:06:14.204446976Z","published":"2025-07-10T09:15:26.377Z","upstream":["CVE-2025-38323"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38323"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.147-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.140-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38323.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.35-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38323.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.35-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38323.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}