Resource management error in Linux kernel 8021q



| Updated: 2025-05-10
Risk Low
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2025-23163
CWE-ID CWE-399
Exploitation vector Local
Public exploit N/A
Vulnerable software
Linux kernel
Operating systems & Components / Operating system

Vendor Linux Foundation

Security Bulletin

This security bulletin contains one low risk vulnerability.

1) Resource management error

EUVDB-ID: #VU108381

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-23163

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the vlan_dev_open(), vlan_dev_stop() and vlan_dev_change_rx_flags() functions in net/8021q/vlan_dev.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Linux kernel: 6.6 - 6.6.87

CPE2.3 External links

https://git.kernel.org/stable/c/27b918007d96402aba10ed52a6af8015230f1793
https://git.kernel.org/stable/c/299d7d27af6b5844cda06a0fdfa635705e1bc50f
https://git.kernel.org/stable/c/523fa0979d842443aa14b80002e45b471cbac137
https://git.kernel.org/stable/c/538b43aa21e3b17c110104efd218b966d2eda5f8
https://git.kernel.org/stable/c/53fb25e90c0a503a17c639341ba5e755cb2feb5c
https://git.kernel.org/stable/c/8980018a9806743d9b80837330d46f06ecf78516
https://git.kernel.org/stable/c/a32f1d4f1f4c9d978698f3c718621f6198f2e7ac
https://git.kernel.org/stable/c/b1e3eeb037256a2f1206a8d69810ec47eb152026
https://git.kernel.org/stable/c/d537859e56bcc3091805c524484a4c85386b3cc8
https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.88


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###