Database/Kernel, userspace & hypervisor
Linux kernel (vsock): vsock binding not kept until socket destruction - use-after-free, local root with a public exploit
CVSS 7.8CVE-2025-21756Kernel, userspace & hypervisorcurated
Impact
vsock binding not kept until socket destruction - use-after-free, local root with a public exploit
Who can reach it
Any tenant process in a container; tenant VM guest
What to do
Livepatchable; otherwise drain + reboot. Blacklist vsock where unused
References
Related entries
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (amdkfd): A correctness defect in the amdkfd (KFD compute driverCVE-2025-21842 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (amdkfd)High
- Linux kernel io_uring: sqe->opcode used unsanitized for table lookups under speculative executionCVE-2025-21863 · Linux kernel io_uring (sqe->opcode speculation sanitization)High
- Linux kernel (drivers/gpu/drm/xe): Xe built its scatter-gather table from HMM page pointers without holding theCVE-2025-21939 · Linux kernel (drivers/gpu/drm/xe)High
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Kernel-mode flaw in the 800-series Ethernet Linux driver (anCVE-2025-22836 · Intel ice driver (Ethernet 800 Series, Linux kernel mode)High
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Kernel-mode flaw in the 800-series Ethernet Linux driverCVE-2025-22893 · Intel ice driver (Ethernet 800 Series, Linux kernel mode)High
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): Kernel-mode flaw in the 800-series Ethernet Linux driver (aCVE-2025-24303 · Intel ice driver (Ethernet 800 Series, Linux kernel mode)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.