{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-21637","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2024-12-29T08:45:45.726Z","datePublished":"2025-01-19T10:17:55.321Z","dateUpdated":"2026-08-05T11:53:17.199Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T11:53:17.199Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: sysctl: udp_port: avoid using current->nsproxy\n\nAs mentioned in a previous commit of this series, using the 'net'\nstructure via 'current' is not recommended for different reasons:\n\n- Inconsistency: getting info from the reader's/writer's netns vs only\n  from the opener's netns.\n\n- current->nsproxy can be NULL in some cases, resulting in an 'Oops'\n  (null-ptr-deref), e.g. when the current task is exiting, as spotted by\n  syzbot [1] using acct(2).\n\nThe 'net' structure can be obtained from the table->data using\ncontainer_of().\n\nNote that table->data could also be used directly, but that would\nincrease the size of this fix, while 'sctp.ctl_sock' still needs to be\nretrieved from 'net' structure."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Despite living in net/sctp/, the vulnerable function is a procfs sysctl ->proc_handler reachable only through local file I/O on /proc/sys/net/sctp/udp_port and local syscalls (acct(2), write(2)); no received SCTP or UDP packet ever reaches it.\nAC:L - Both trigger paths are fully deterministic and entirely attacker-driven — either unshare/open/SCM_RIGHTS/write for the netns-confusion path, or acct(2) plus `umount -l` plus process exit for the NULL deref — with no race, no victim state, and no memory-layout dependency.\nPR:L - An unprivileged user can reach the flaw via `unshare -Urn`, since cap_capable() grants the owner of a child user namespace CAP_NET_ADMIN over it (security/commoncap.c:92), letting a process still in the init netns write through the child's sysctl fd and have the handler act on init_net; no real root is needed for that path.\nUI:N - The attacker performs every step from its own cooperating processes — namespace creation, fd passing, the write, or its own exit — with no action required from any other user or administrator.\nS:U - The flawed code and the affected resources are both kernel network-namespace state within the same kernel security authority; no hypervisor, IOMMU, or VM boundary is crossed.\nC:N - The NULL+offset dereference faults before returning any data, and the read side of the netns confusion only reports the caller's own netns value for a world-readable (0644) setting, so no protected information is disclosed.\nI:H - The netns confusion lets an unprivileged local user write init_net.sctp.udp_port and drive sctp_udp_sock_stop()/sctp_udp_sock_start() on the host namespace, fully controlling whether and on which port the host kernel decapsulates SCTP from UDP — an attacker-chosen modification of protected host network state and a bypass of SCTP packet filtering.\nA:H - The NULL-ptr-deref oops fires inside do_exit() while acct->lock is held, wedging the exiting task with a stuck mutex and pinned mount and panicking outright on panic_on_oops builds; separately, the cross-netns write destroys the host's SCTP UDP tunnel sockets, severing SCTP-over-UDP connectivity."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sctp/sysctl.c"],"versions":[{"version":"046c052b475e7119b6a30e3483e2888fc606a2f8","lessThan":"0a0966312ac3eedd7f5f2a766ed4702df39a9a65","status":"affected","versionType":"git"},{"version":"046c052b475e7119b6a30e3483e2888fc606a2f8","lessThan":"e919197fb8616331f5dc81e4c3cc3d12769cb725","status":"affected","versionType":"git"},{"version":"046c052b475e7119b6a30e3483e2888fc606a2f8","lessThan":"55627918febdf9d71107a1e68d1528dc591c9a15","status":"affected","versionType":"git"},{"version":"046c052b475e7119b6a30e3483e2888fc606a2f8","lessThan":"5b77d73f3be5102720fb685b9e6900e3500e1096","status":"affected","versionType":"git"},{"version":"046c052b475e7119b6a30e3483e2888fc606a2f8","lessThan":"c10377bbc1972d858eaf0ab366a311b39f8ef1b6","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["net/sctp/sysctl.c"],"versions":[{"version":"5.11","status":"affected"},{"version":"0","lessThan":"5.11","status":"unaffected","versionType":"semver"},{"version":"5.15.177","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.125","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.72","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.10","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.13","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"5.15.177"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"6.1.125"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"6.6.72"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"6.12.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.11","versionEndExcluding":"6.13"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/0a0966312ac3eedd7f5f2a766ed4702df39a9a65"},{"url":"https://git.kernel.org/stable/c/e919197fb8616331f5dc81e4c3cc3d12769cb725"},{"url":"https://git.kernel.org/stable/c/55627918febdf9d71107a1e68d1528dc591c9a15"},{"url":"https://git.kernel.org/stable/c/5b77d73f3be5102720fb685b9e6900e3500e1096"},{"url":"https://git.kernel.org/stable/c/c10377bbc1972d858eaf0ab366a311b39f8ef1b6"}],"title":"sctp: sysctl: udp_port: avoid using current->nsproxy","x_generator":{"engine":"bippy-1.2.0"}},"adp":[{"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":5.5,"attackVector":"LOCAL","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"NONE"}},{"other":{"type":"ssvc","content":{"id":"CVE-2025-21637","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"version":"2.0.3","timestamp":"2025-10-01T19:54:10.551212Z"}}}],"problemTypes":[{"descriptions":[{"lang":"en","type":"CWE","cweId":"CWE-476","description":"CWE-476 NULL Pointer Dereference"}]}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-01T19:57:17.821Z"}},{"title":"CVE Program Container","references":[{"url":"https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2025-11-03T20:58:15.076Z"}}]}}