CVE-2025-38180

Source
https://cve.org/CVERecord?id=CVE-2025-38180
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38180.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-38180
Downstream
Related
Published
2025-07-04T13:37:08.258Z
Modified
2026-03-20T12:42:43.349752Z
Summary
net: atm: fix /proc/net/atm/lec handling
Details

In the Linux kernel, the following vulnerability has been resolved:

net: atm: fix /proc/net/atm/lec handling

/proc/net/atm/lec must ensure safety against dev_lec[] changes.

It appears it had devput() calls without prior devhold(), leading to imbalance and UAF.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/38xxx/CVE-2025-38180.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Fixed
fcfccf56f4eba7d00aa2d33c7bb1b33083237742
Fixed
f2d1443b18806640abdb530e88009af7be2588e7
Fixed
ca3829c18c8d0ceb656605d3bff6bb3dfb078589
Fixed
e612c4b014f5808fbc6beae21f5ccaca5e76a2f8
Fixed
a5e3a144268899f1a8c445c8a3bfa15873ba85e8
Fixed
5fe1b23a2f87f43aeeac51e08819cbc6fd808cbc
Fixed
9b9aeb3ada44d8abea1e31e4446113f460848ae4
Fixed
d03b79f459c7935cff830d98373474f440bd03ae

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-38180.json"