CVE-2025-22111

Aliases:UBUNTU-CVE-2025-22111DEBIAN-CVE-2025-22111CGA-246w-cr28-4349CGA-26pc-cwvf-xw43CGA-28rp-f4cg-hxfpCGA-2c4g-cf4w-5fp9CGA-2f76-6x86-6v7pCGA-2f86-jp9w-xr32CGA-2hvc-fwh2-264pCGA-2jc7-m3g5-2w29CGA-2r4j-3645-8479CGA-336r-rx9f-pprmCGA-37f5-cg84-c9jvCGA-39rr-xwqj-qjr7CGA-3crw-vc8r-5mxhCGA-3gx2-gm8q-fq8gCGA-3x44-p4wh-f5vjCGA-43rc-f4wf-55wmCGA-4f8m-wcq7-p9qcCGA-4jvf-3rj9-wx7gCGA-4wj5-fpxg-8722CGA-4x86-3g5w-9fc3CGA-4xfg-h74x-32h7CGA-57fm-7474-qj99CGA-5g5c-3vr9-x99rCGA-5jx2-gqqx-v7mmCGA-5v7p-4j7m-2vpxCGA-6323-6fxj-8vpwCGA-654r-6cqw-533gCGA-656j-gw4h-6843CGA-6954-73m4-5xj8CGA-695v-5x25-wvgfCGA-6w47-8wqr-wmgmCGA-728c-4225-9f45CGA-767c-9qq2-5w6qCGA-769w-7hjx-qfm5CGA-77rg-2hpg-jqqfCGA-794f-v2rx-x6rvCGA-7fww-2m4v-7ch9CGA-7mm9-c2gq-x773CGA-7v4p-ww6p-wf5fCGA-88cx-7cp6-f58jCGA-8mhg-68gw-vghrCGA-8q8h-39hm-25xxCGA-8rrf-2594-q4h6CGA-8vp2-qwr5-9g26CGA-8wc8-3xvf-9vf3CGA-92mp-q7cv-xpg9CGA-966v-5wxf-528gCGA-9gmm-gqjh-qjx2CGA-9grp-q94m-cppmCGA-9pf7-96mc-hpwgCGA-9qvw-2wh7-v4xgCGA-9rp2-hqhp-q5c9CGA-9v45-vv89-3vr9CGA-c6j7-wf7m-qf4gCGA-cxrr-4rcf-gh83CGA-fq5q-4mhp-6p7mCGA-fr6m-8x55-vjjwCGA-fxrr-c8x3-6p3gCGA-g295-vw33-f445CGA-g3jc-97pc-94hcCGA-g55q-jp85-q2hpCGA-g6hc-rvm6-898qCGA-h9c6-r7wm-23gqCGA-hfw9-953g-r6r2CGA-hjfq-qw62-5hm9CGA-hqmp-26v5-6mmvCGA-hr77-mg76-jp6qCGA-hv94-jj5g-jvgcCGA-hxm6-g62p-wxh4CGA-j4m9-38cw-9f37CGA-j4vv-hvx4-v8w2CGA-j5jg-27rv-9385CGA-j6cf-mv6j-pw63CGA-j934-42h8-g2xcCGA-jcx5-rvwc-hmpcCGA-jm4w-x622-p3hxCGA-jrcc-c2mf-pgjwCGA-jv4r-4hpv-qx85CGA-mp23-399w-pm39CGA-mqrg-578r-32hcCGA-p2r9-v8x2-m4p7CGA-p2vv-99fg-9x55CGA-p59q-8qf8-cjh2CGA-pp6x-3gxx-px44CGA-pw2v-qfm7-q42vCGA-q4jr-4q8j-36w5CGA-q4m7-mr84-3jmvCGA-qg4c-f62x-8px2CGA-qvf9-hhwq-7pc4CGA-r889-rg68-hgq4CGA-r8f8-g4px-jx9fCGA-r988-j5hm-248cCGA-r9h4-4fr3-7x5cCGA-rcg3-m6ff-x5j2CGA-rjrp-9jv3-cxfjCGA-rp4m-cgmp-q5wqCGA-rpch-83g4-j4mhCGA-rx86-g4c2-cccrCGA-v54r-3cgc-pxxjCGA-v5vf-qwv6-9vrpCGA-v6px-mqgh-8wfgCGA-vgpj-5f2f-8jgxCGA-vjh3-8gx7-92pqCGA-w38r-686p-w93hCGA-w4vw-xg3r-p5xcCGA-w8h4-wf9p-97h8CGA-w8rp-v734-gvq7CGA-wcmq-pfgr-mjg9CGA-ww6r-8r9x-54rhCGA-wx2m-qwr5-2g2wCGA-wxc6-53wx-gjf4CGA-xcg7-m9xj-m9fgCGA-xgf5-256q-2jfwCGA-xh73-gcx5-vw84CGA-xqqr-28v8-q423CGA-xw27-6jcm-53rrCGA-xx33-2mcq-9g32CGA-xx98-h82x-m7v7
Advisory lineage Upstream: 0 Downstream: 45
Modified
Published: 16 Apr 2025, 14:12
Last modified:08 Sept 2026, 08:41

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.21% LOW
0% probability +0.16%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Apr 2025, 14:12
Published
Vulnerability first disclosed
08 Sept 2026, 08:41
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: net: Remove RTNL dance for SIOCBRADDIF and SIOCBRDELIF. SIOCBRDELIF is passed to dev_ioctl() first and later forwarded to br_ioctl_call(), which causes unnecessary RTNL dance and the splat below [0] under RTNL pressure. Let's say Thread A is trying to detach a device from a bridge and Thread B is trying to remove the bridge. In dev_ioctl(), Thread A bumps the bridge device's refcnt by netdev_hold() and releases RTNL because the following br_ioctl_call() also re-acquires RTNL. In the race window, Thread B could acquire RTNL and try to remove the bridge device. Then, rtnl_unlock() by Thread B will release RTNL and wait for netdev_put() by Thread A. Thread A, however, must hold RTNL after the unlock in dev_ifsioc(), which may take long under RTNL pressure, resulting in the splat by Thread B. Thread A (SIOCBRDELIF) Thread B (SIOCBRDELBR) ---------------------- ---------------------- sock_ioctl sock_ioctl `- sock_do_ioctl `- br_ioctl_call `- dev_ioctl `- br_ioctl_stub |- rtnl_lock | |- dev_ifsioc ' ' |- dev = __dev_get_by_name(...) |- netdev_hold(dev, ...) . / |- rtnl_unlock ------. | | |- br_ioctl_call `---> |- rtnl_lock Race | | `- br_ioctl_stub |- br_del_bridge Window | | | |- dev = __dev_get_by_name(...) | | | May take long | `- br_dev_delete(dev, ...) | | | under RTNL pressure | `- unregister_netdevice_queue(dev, ...) | | | | `- rtnl_unlock \ | |- rtnl_lock <-' `- netdev_run_todo | |- ... `- netdev_run_todo | `- rtnl_unlock |- __rtnl_unlock | |- netdev_wait_allrefs_any |- netdev_put(dev, ...) <----------------' Wait refcnt decrement and log splat below To avoid blocking SIOCBRDELBR unnecessarily, let's not call dev_ioctl() for SIOCBRADDIF and SIOCBRDELIF. In the dev_ioctl() path, we do the following: 1. Copy struct ifreq by get_user_ifreq in sock_do_ioctl() 2. Check CAP_NET_ADMIN in dev_ioctl() 3. Call dev_load() in dev_ioctl() 4. Fetch the master dev from ifr.ifr_name in dev_ifsioc() 3. can be done by request_module() in br_ioctl_call(), so we move 1., 2., and 4. to br_ioctl_stub(). Note that 2. is also checked later in add_del_if(), but it's better performed before RTNL. SIOCBRADDIF and SIOCBRDELIF have been processed in dev_ioctl() since the pre-git era, and there seems to be no specific reason to process them there. [0]: unregister_netdevice: waiting for wpan3 to become free. Usage count = 2 ref_tracker: wpan3@ffff8880662d8608 has 1/1 users at __netdev_tracker_alloc include/linux/netdevice.h:4282 [inline] netdev_hold include/linux/netdevice.h:4311 [inline] dev_ifsioc+0xc6a/0x1160 net/core/dev_ioctl.c:624 dev_ioctl+0x255/0x10c0 net/core/dev_ioctl.c:826 sock_do_ioctl+0x1ca/0x260 net/socket.c:1213 sock_ioctl+0x23a/0x6c0 net/socket.c:1318 vfs_ioctl fs/ioctl.c:51 [inline] __do_sys_ioctl fs/ioctl.c:906 [inline] __se_sys_ioctl fs/ioctl.c:892 [inline] __x64_sys_ioctl+0x1a4/0x210 fs/ioctl.c:892 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcb/0x250 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.21% Percentile: 11%

Affected Systems

  • chainguardlinux-aws-6.12

    < 6.12.76-r0 | < 6.12.68-r0 | < 6.12.62-r1 | < 6.12.57-r2 | < 6.12.62-r2 | < 6.12.63-r0 | < 6.12.71-r0 | < 6.12.77-r0 | < 6.12.72-r0 | < 6.12.74-r1 | < 6.12.74-r0 | < 6.12.77-r2 | < 6.12.62-r0 | < 6.12.65-r2 | < 6.12.80-r0 | < 6.12.77-r1 | < 6.12.70-r0 | < 6.12.78-r0 | < 6.12.72-r1 | < 6.12.67-r0 | < 6.12.65-r1 | < 6.12.69-r0 | < 6.12.68-r1 | < 6.12.65-r0 | < 6.12.60-r4 | < 6.12.66-r0

  • chainguardlinux-azure-6.12

    < 6.12.66-r0 | < 6.12.65-r2 | < 6.12.68-r0 | < 6.12.57-r2 | < 6.12.62-r0 | < 6.12.77-r2 | < 6.12.74-r0 | < 6.12.62-r2 | < 6.12.65-r1 | < 6.12.60-r3 | < 6.12.67-r0 | < 6.12.77-r0 | < 6.12.72-r0 | < 6.12.69-r0 | < 6.12.74-r1 | < 6.12.60-r4 | < 6.12.62-r1 | < 6.12.63-r0 | < 6.12.65-r4 | < 6.12.78-r0 | < 6.12.80-r0 | < 6.12.65-r3 | < 6.12.77-r1 | < 6.12.76-r0 | < 6.12.71-r0 | < 6.12.70-r0

  • chainguardlinux-gcp-6.12

    < 6.12.63-r0 | < 6.12.65-r1 | < 6.12.62-r0 | < 6.12.72-r0 | < 6.12.74-r1 | < 6.12.76-r0 | < 6.12.77-r1 | < 6.12.57-r2 | < 6.12.71-r0 | < 6.12.62-r1 | < 6.12.77-r2 | < 6.12.80-r0 | < 6.12.68-r0 | < 6.12.70-r0 | < 6.12.78-r0 | < 6.12.69-r0 | < 6.12.65-r0 | < 6.12.68-r1 | < 6.12.60-r3 | < 6.12.66-r0 | < 6.12.62-r2 | < 6.12.65-r2 | < 6.12.60-r4 | < 6.12.74-r0 | < 6.12.67-r0 | < 6.12.77-r0

  • chainguardlinux-qemu-6.12

    < 6.12.68-r0 | < 6.12.65-r1 | < 6.12.80-r0 | < 6.12.77-r2 | < 6.12.74-r0 | < 6.12.78-r0 | < 6.12.69-r0 | < 6.12.77-r1 | < 6.12.65-r2 | < 6.12.70-r0 | < 6.12.67-r0 | < 6.12.66-r0 | < 6.12.77-r0 | < 6.12.72-r0 | < 6.12.71-r0 | < 6.12.76-r0 | < 6.12.74-r1

  • chainguardlinux-vmware-6.12

    < 6.12.67-r0 | < 6.12.68-r1 | < 6.12.77-r0 | < 6.12.78-r0 | < 6.12.68-r0 | < 6.12.72-r0 | < 6.12.77-r2 | < 6.12.69-r0 | < 6.12.76-r0 | < 6.12.77-r1 | < 6.12.70-r0 | < 6.12.65-r1 | < 6.12.74-r1 | < 6.12.74-r0 | < 6.12.71-r0 | < 6.12.66-r0 | < 6.12.65-r2 | < 6.12.80-r0

  • debianlinux

    < 6.1.162-1 | < 6.12.69-1 | < 6.16.3-1

  • debianlinux-6.1

    < 6.1.162-1~deb11u1

  • ubuntulinux

    < 5.15.0-173.183 | < 6.8.0-110.110

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    < 5.15.0-1103.110 | < 6.8.0-1052.55

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    < 5.15.0-1103.110~20.04.1

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    < 6.8.0-1052.55~22.04.1

  • ubuntulinux-aws-fips

    all | < 5.15.0-1103.110+fips1 | < 6.8.0-1052.55+fips1

  • ubuntulinux-azure

    all | < 5.15.0-1109.118 | < 6.8.0-1054.60

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    < 5.15.0-1110.119~20.04.1

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-6.8

    < 6.8.0-1059.65~22.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | all | all | all

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fde-6.2

    all

  • ubuntulinux-azure-fde-6.8

    all

  • ubuntulinux-azure-fips

    all | < 5.15.0-1109.118+fips1 | < 6.8.0-1053.59+fips1

  • ubuntulinux-azure-nvidia

    all

  • ubuntulinux-bluefield

    all | < 5.15.0-1086.88 | < 6.8.0-1017.21

  • ubuntulinux-fips

    all | < 5.15.0-173.183+fips1 | < 6.8.0-110.110+fips2

  • ubuntulinux-gcp

    all | < 5.15.0-1103.112 | < 6.8.0-1054.57

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.15

    < 5.15.0-1103.112~20.04.1

  • ubuntulinux-gcp-5.19

    all

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.8

    all

  • ubuntulinux-gcp-6.11

    all

  • ubuntulinux-gcp-6.2

    all

Showing first 50 affected entries in server-rendered view.

References (38)