Use-After-Free Vulnerability in IBM Virtual Network Interface Driver
CVE-2025-21855
Summary
A vulnerability exists in the IBM Virtual Network Interface Driver (IBMVNIC) due to improper handling of socket buffers (SKBs) after transmission to the Virtual I/O Server (VIOS). When an SKB is sent, the driver incorrectly allows further access to the SKB memory. The VIOS can subsequently free this memory, leading to a potential race condition between reading the length of the SKB and the freeing operation, resulting in a use-after-free scenario. This can lead to unpredictable behavior and can compromise system integrity, especially during low-path management operations.
Affected Version(s)
Linux 032c5e82847a2214c3196a90f0aeba0ce252de58 < 501ac6a7e21b82e05207c6b4449812d82820f306
Linux 032c5e82847a2214c3196a90f0aeba0ce252de58 < 093b0e5c90592773863f300b908b741622eef597
Linux 032c5e82847a2214c3196a90f0aeba0ce252de58 < 25dddd01dcc8ef3acff964dbb32eeb0d89f098e9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved