during an AF_VSOCK connect syscall can occur before a worker thread accesses it resulting in a dangling pointer and potential kernel code execution.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11484 | A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure during an AF_VSOCK connect syscall can occur before a worker thread accesses it resulting in a dangling pointer and potential kernel code execution. |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Google
Google chrome Os Linux Linux linux Kernel |
|
| CPEs | cpe:2.3:o:google:chrome_os:15474.84.0:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:5.4:-:*:*:*:*:*:* |
|
| Vendors & Products |
Google
Google chrome Os Linux Linux linux Kernel |
Thu, 17 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-416 | |
| Metrics |
cvssV3_1
|
Thu, 17 Apr 2025 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure during an AF_VSOCK connect syscall can occur before a worker thread accesses it, resulting in a dangling pointer and potential kernel code execution. | A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure during an AF_VSOCK connect syscall can occur before a worker thread accesses it resulting in a dangling pointer and potential kernel code execution. |
Thu, 17 Apr 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtio_vsock_sock structure during an AF_VSOCK connect syscall can occur before a worker thread accesses it, resulting in a dangling pointer and potential kernel code execution. | |
| References |
|
Status: PUBLISHED
Assigner: ChromeOS
Published:
Updated: 2025-05-08T19:15:07.309Z
Reserved: 2025-02-13T22:19:47.467Z
Link: CVE-2025-1290
Updated: 2025-04-17T13:26:29.180Z
Status : Analyzed
Published: 2025-04-17T01:15:46.317
Modified: 2025-07-11T13:55:52.760
Link: CVE-2025-1290
No data.
OpenCVE Enrichment
No data.
EUVD