#VU110685 Improper locking in Linux kernel - CVE-2025-38004


Vulnerability identifier: #VU110685

Vulnerability risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2025-38004

CWE-ID: CWE-667

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Linux kernel
Operating systems & Components / Operating system

Vendor: Linux Foundation

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the bcm_can_tx(), bcm_tx_timeout_handler() and bcm_tx_setup() functions in net/can/bcm.c. A local user can perform a denial of service (DoS) attack.

Mitigation
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Vulnerable software versions

Linux kernel: All versions


External links
https://git.kernel.org/stable/c/2a437b86ac5a9893c902f30ef66815bf13587bf6
https://git.kernel.org/stable/c/7595de7bc56e0e52b74e56c90f7e247bf626d628
https://git.kernel.org/stable/c/76c84c3728178b2d38d5604e399dfe8b0752645e
https://git.kernel.org/stable/c/8f1c022541bf5a923c8d6fa483112c15250f30a4
https://git.kernel.org/stable/c/c2aba69d0c36a496ab4f2e81e9c2b271f2693fd7
https://git.kernel.org/stable/c/c4e8a172501e677ebd8ea9d9161d97dc4df56fbd
https://git.kernel.org/stable/c/cc55dd28c20a6611e30596019b3b2f636819a4c0
https://git.kernel.org/stable/c/fbd8fdc2b218e979cfe422b139b8f74c12419d1f


Q & A

Can this vulnerability be exploited remotely?

Is there known malware, which exploits this vulnerability?


Latest bulletins with this vulnerability