{"id":"DEBIAN-CVE-2025-38666","details":"In the Linux kernel, the following vulnerability has been resolved:  net: appletalk: Fix use-after-free in AARP proxy probe  The AARP proxy‐probe routine (aarp_proxy_probe_network) sends a probe, releases the aarp_lock, sleeps, then re-acquires the lock.  During that window an expire timer thread (__aarp_expire_timer) can remove and kfree() the same entry, leading to a use-after-free.  race condition:           cpu 0                          |            cpu 1     atalk_sendmsg()                     |   atif_proxy_probe_device()     aarp_send_ddp()                     |   aarp_proxy_probe_network()     mod_timer()                         |   lock(aarp_lock) // LOCK!!     timeout around 200ms                |   alloc(aarp_entry)     and then call                       |   proxies[hash] = aarp_entry     aarp_expire_timeout()               |   aarp_send_probe()                                         |   unlock(aarp_lock) // UNLOCK!!     lock(aarp_lock) // LOCK!!           |   msleep(100);     __aarp_expire_timer(&proxies[ct])   |     free(aarp_entry)                    |     unlock(aarp_lock) // UNLOCK!!       |                                         |   lock(aarp_lock) // LOCK!!                                         |   UAF aarp_entry !!  ================================================================== BUG: KASAN: slab-use-after-free in aarp_proxy_probe_network+0x560/0x630 net/appletalk/aarp.c:493 Read of size 4 at addr ffff8880123aa360 by task repro/13278  CPU: 3 UID: 0 PID: 13278 Comm: repro Not tainted 6.15.2 #3 PREEMPT(full) Call Trace:  \u003cTASK\u003e  __dump_stack lib/dump_stack.c:94 [inline]  dump_stack_lvl+0x116/0x1b0 lib/dump_stack.c:120  print_address_description mm/kasan/report.c:408 [inline]  print_report+0xc1/0x630 mm/kasan/report.c:521  kasan_report+0xca/0x100 mm/kasan/report.c:634  aarp_proxy_probe_network+0x560/0x630 net/appletalk/aarp.c:493  atif_proxy_probe_device net/appletalk/ddp.c:332 [inline]  atif_ioctl+0xb58/0x16c0 net/appletalk/ddp.c:857  atalk_ioctl+0x198/0x2f0 net/appletalk/ddp.c:1818  sock_do_ioctl+0xdc/0x260 net/socket.c:1190  sock_ioctl+0x239/0x6a0 net/socket.c:1311  vfs_ioctl fs/ioctl.c:51 [inline]  __do_sys_ioctl fs/ioctl.c:906 [inline]  __se_sys_ioctl fs/ioctl.c:892 [inline]  __x64_sys_ioctl+0x194/0x200 fs/ioctl.c:892  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]  do_syscall_64+0xcb/0x250 arch/x86/entry/syscall_64.c:94  entry_SYSCALL_64_after_hwframe+0x77/0x7f  \u003c/TASK\u003e  Allocated:  aarp_alloc net/appletalk/aarp.c:382 [inline]  aarp_proxy_probe_network+0xd8/0x630 net/appletalk/aarp.c:468  atif_proxy_probe_device net/appletalk/ddp.c:332 [inline]  atif_ioctl+0xb58/0x16c0 net/appletalk/ddp.c:857  atalk_ioctl+0x198/0x2f0 net/appletalk/ddp.c:1818  Freed:  kfree+0x148/0x4d0 mm/slub.c:4841  __aarp_expire net/appletalk/aarp.c:90 [inline]  __aarp_expire_timer net/appletalk/aarp.c:261 [inline]  aarp_expire_timeout+0x480/0x6e0 net/appletalk/aarp.c:317  The buggy address belongs to the object at ffff8880123aa300  which belongs to the cache kmalloc-192 of size 192 The buggy address is located 96 bytes inside of  freed 192-byte region [ffff8880123aa300, ffff8880123aa3c0)  Memory state around the buggy address:  ffff8880123aa200: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ffff8880123aa280: 00 00 00 00 fc fc fc fc fc fc fc fc fc fc fc fc \u003effff8880123aa300: fa fb fb fb fb fb fb fb fb fb fb fb fb fb fb fb                                                        ^  ffff8880123aa380: fb fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc  ffff8880123aa400: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ==================================================================","modified":"2026-09-01T16:06:15.310785804Z","published":"2025-08-22T16:15:42Z","upstream":["CVE-2025-38666"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-38666"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.148-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.140-1","6.1.147-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38666.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.41-1"}]}],"versions":["6.12.38-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38666.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.16.3-1"}]}],"versions":["6.12.100-1","6.12.101-1","6.12.105-1","6.12.107-1","6.12.38-1","6.12.41-1","6.12.43-1","6.12.43-1~bpo12+1","6.12.48-1","6.12.57-1","6.12.57-1~bpo12+1","6.12.63-1","6.12.63-1~bpo12+1","6.12.69-1","6.12.69-1~bpo12+1","6.12.73-1","6.12.73-1~bpo12+1","6.12.74-1","6.12.74-2","6.12.74-2~bpo12+1","6.12.85-1","6.12.85-1~bpo12+1","6.12.86-1","6.12.86-1~bpo12+1","6.12.88-1","6.12.88-1~bpo12+1","6.12.90-1","6.12.90-1~bpo12+1","6.12.90-2","6.12.90-2~bpo12+1","6.12.94-1","6.12.94-1~bpo12+1","6.12.95-1","6.12.95-1~bpo12+1","6.12.96-1","6.13.10-1~exp1","6.13.11-1~exp1","6.13.2-1~exp1","6.13.3-1~exp1","6.13.4-1~exp1","6.13.5-1~exp1","6.13.6-1~exp1","6.13.7-1~exp1","6.13.8-1~exp1","6.13.9-1~exp1","6.13~rc6-1~exp1","6.13~rc7-1~exp1","6.14.3-1~exp1","6.14.5-1~exp1","6.14.6-1~exp1","6.15-1~exp1","6.15.1-1~exp1","6.15.2-1~exp1","6.15.3-1~exp1","6.15.4-1~exp1","6.15.5-1~exp1","6.15.6-1~exp1","6.15~rc7-1~exp1","6.16-1~exp1","6.16.1-1~exp1","6.16.3-1~bpo13+1","6.16~rc7-1~exp1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-38666.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}