CVE-2025-71182
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: can: j1939: make j1939_session_activate() fail if device is no longer registered syzbot is still reporting unregister_netdevice: waiting for vcan0 to become free. Usage count = 2 even after commit 93a27b5891b8 ("can: j1939: add missing calls in NETDEV_UNREGISTER notification handler") was added. A debug printk() patch found that j1939_session_activate() can succeed even after j1939_cancel_active_session() from j1939_netdev_notify(NETDEV_UNREGISTER) has completed. Since j1939_cancel_active_session() is processed with the session list lock held, checking ndev->reg_state in j1939_session_activate() with the session list lock held can reliably close the race window.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.01%• Percentile: 1%
Affected Systems
- linux•linux
≥ 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < ebb0dfd718dd31c8d3600612ca4b7207ec3d923a | ≥ 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < c3a4316e3c746af415c0fd6c6d489ad13f53714d | ≥ 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 46ca9dc978923c5e1247a9e9519240ba7ace413c | ≥ 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 78d87b72cebe2a993fd5b017e9f14fb6278f2eae | ≥ 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < ba6f0d1832eeb5eb3a6dc5cb30e0f720b3cb3536 | ≥ 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 79dd3f1d9dd310c2af89b09c71f34d93973b200f | ≥ 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2, < 5d5602236f5db19e8b337a2cd87a90ace5ea776d | ≥ 9d71dd0c70099914fcd063135da3c580865e924c, < ebb0dfd718dd31c8d3600612ca4b7207ec3d923a | ≥ 9d71dd0c70099914fcd063135da3c580865e924c, < c3a4316e3c746af415c0fd6c6d489ad13f53714d | ≥ 9d71dd0c70099914fcd063135da3c580865e924c, < 46ca9dc978923c5e1247a9e9519240ba7ace413c | ≥ 9d71dd0c70099914fcd063135da3c580865e924c, < 78d87b72cebe2a993fd5b017e9f14fb6278f2eae | ≥ 9d71dd0c70099914fcd063135da3c580865e924c, < ba6f0d1832eeb5eb3a6dc5cb30e0f720b3cb3536 | ≥ 9d71dd0c70099914fcd063135da3c580865e924c, < 79dd3f1d9dd310c2af89b09c71f34d93973b200f | ≥ 9d71dd0c70099914fcd063135da3c580865e924c, < 5d5602236f5db19e8b337a2cd87a90ace5ea776d | 5.4
- linux•linux_kernel
≥ 5.4.1, < 5.10.248 | ≥ 5.11, < 5.15.198 | ≥ 5.16, < 6.1.161 | ≥ 6.2, < 6.6.121 | ≥ 6.7, < 6.12.66 | ≥ 6.13, < 6.18.6 | 5.4 | 6.19:rc1 | 6.19:rc2 | 6.19:rc3 | 6.19:rc4 | 6.19:rc5 | 6.19:rc6 | 6.19:rc7 | 6.19:rc8
References (7)
- https://git.kernel.org/stable/c/ebb0dfd718dd31c8d3600612ca4b7207ec3d923a
- https://git.kernel.org/stable/c/c3a4316e3c746af415c0fd6c6d489ad13f53714d
- https://git.kernel.org/stable/c/46ca9dc978923c5e1247a9e9519240ba7ace413c
- https://git.kernel.org/stable/c/78d87b72cebe2a993fd5b017e9f14fb6278f2eae
- https://git.kernel.org/stable/c/ba6f0d1832eeb5eb3a6dc5cb30e0f720b3cb3536
- https://git.kernel.org/stable/c/79dd3f1d9dd310c2af89b09c71f34d93973b200f
- https://git.kernel.org/stable/c/5d5602236f5db19e8b337a2cd87a90ace5ea776d