CVE-2025-38180

Source
https://cve.org/CVERecord?id=CVE-2025-38180
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38180.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38180
Downstream
Related
Published
2025-07-04T13:37:08.258Z
Modified
2026-05-07T04:18:38.279167Z
Summary
net: atm: fix /proc/net/atm/lec handling
Details

In the Linux kernel, the following vulnerability has been resolved:

net: atm: fix /proc/net/atm/lec handling

/proc/net/atm/lec must ensure safety against dev_lec[] changes.

It appears it had devput() calls without prior devhold(), leading to imbalance and UAF.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38180.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed
fcfccf56f4eba7d00aa2d33c7bb1b33083237742
Fixed
f2d1443b18806640abdb530e88009af7be2588e7
Fixed
ca3829c18c8d0ceb656605d3bff6bb3dfb078589
Fixed
e612c4b014f5808fbc6beae21f5ccaca5e76a2f8
Fixed
a5e3a144268899f1a8c445c8a3bfa15873ba85e8
Fixed
5fe1b23a2f87f43aeeac51e08819cbc6fd808cbc
Fixed
9b9aeb3ada44d8abea1e31e4446113f460848ae4
Fixed
d03b79f459c7935cff830d98373474f440bd03ae

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38180.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.12
Fixed
5.4.295
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.239
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.186
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.142
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.95
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.35
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.15.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38180.json"