FlawAtlas
Search the atlas
CVE-2025-38618 Not scored

vsock: Do not allow binding to VMADDR_PORT_ANY

In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It is possible for a vsock to autobind to VMADDR_PORT_ANY. This can cause a use-after-free when a connection is made to the bound socket. The socket returned by accept() also has port VMADDR_PORT_ANY but is not on the list of unbound sockets. Binding it will result in an extra refcount decrement similar to the one fixed in fcdd2242c023 (vsock: Keep the binding until socket destruction). Modify the check in __vsock_bind_connectible() to also prevent binding to VMADDR_PORT_ANY.

Exploit probability 0.2%
Published August 22, 2025
Required by Not available
Last source change July 15, 2026

02 / AFFECTED SOFTWARE

Affected packages

Android :linux_kernel:

1 explicit affected versions

Linux Kernel
Unknown Unknown

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2025:20081-1
related SUSE-SU-2025:03204-1
related SUSE-SU-2025:03272-1
related SUSE-SU-2025:03283-1
related SUSE-SU-2025:03290-1
related SUSE-SU-2025:03301-1
related SUSE-SU-2025:03310-1
related SUSE-SU-2025:03314-1
related SUSE-SU-2025:03344-1
related SUSE-SU-2025:03382-1
related SUSE-SU-2025:03383-1
related SUSE-SU-2025:03384-1
related SUSE-SU-2025:03602-1
related SUSE-SU-2025:03633-1
related SUSE-SU-2025:03634-1
related SUSE-SU-2025:20653-1
related SUSE-SU-2025:20669-1
related SUSE-SU-2025:20739-1
related SUSE-SU-2025:20756-1
related SUSE-SU-2025:20939-1
related SUSE-SU-2025:20940-1
related SUSE-SU-2025:20941-1
related SUSE-SU-2025:20942-1
related SUSE-SU-2025:20943-1
related SUSE-SU-2025:20944-1
related SUSE-SU-2025:20945-1
related SUSE-SU-2025:20946-1
related SUSE-SU-2025:20947-1
related SUSE-SU-2025:20949-1
related SUSE-SU-2025:20950-1
related SUSE-SU-2025:20951-1
related SUSE-SU-2025:20952-1
related SUSE-SU-2025:20953-1
related SUSE-SU-2025:20955-1
related SUSE-SU-2025:20956-1
related SUSE-SU-2025:20957-1
related SUSE-SU-2025:20959-1
related SUSE-SU-2025:20960-1
related SUSE-SU-2025:20972-1
related SUSE-SU-2025:20973-1
related SUSE-SU-2025:20974-1
related SUSE-SU-2025:20975-1
related SUSE-SU-2025:20977-1
related SUSE-SU-2025:20978-1
related SUSE-SU-2025:20980-1
related SUSE-SU-2025:20981-1
related SUSE-SU-2025:20982-1
related SUSE-SU-2025:20983-1
related SUSE-SU-2025:20984-1
related SUSE-SU-2025:20985-1
related SUSE-SU-2025:20986-1
related SUSE-SU-2025:20987-1
related SUSE-SU-2025:20988-1
related SUSE-SU-2025:20989-1
related SUSE-SU-2025:20991-1
related SUSE-SU-2025:21074-1
related SUSE-SU-2025:21139-1
related SUSE-SU-2025:21179-1
related SUSE-SU-2025:3878-1
related SUSE-SU-2025:3880-1
related SUSE-SU-2025:3886-1
related SUSE-SU-2025:3888-1
related SUSE-SU-2025:3892-1
related SUSE-SU-2025:3927-1
related SUSE-SU-2025:3932-1
related SUSE-SU-2025:3935-1
related SUSE-SU-2025:3936-1
related SUSE-SU-2025:3983-1
related SUSE-SU-2025:3987-1
related SUSE-SU-2025:3995-1
related SUSE-SU-2025:4000-1
related SUSE-SU-2025:4001-1
related SUSE-SU-2025:4016-1
related SUSE-SU-2025:4024-1
related SUSE-SU-2025:4031-1
related SUSE-SU-2025:4036-1
related SUSE-SU-2025:4040-1
related SUSE-SU-2025:4043-1
related SUSE-SU-2025:4046-1
related SUSE-SU-2025:4050-1
related SUSE-SU-2025:4056-1
related SUSE-SU-2025:4058-1
related SUSE-SU-2025:4059-1
related SUSE-SU-2025:4062-1
related SUSE-SU-2025:4063-1
related SUSE-SU-2025:4064-1
related SUSE-SU-2025:4078-1
related SUSE-SU-2025:4123-1
related SUSE-SU-2026:20149-1
related SUSE-SU-2026:20164-1
related SUSE-SU-2026:20169-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities ASB-A-439253642

In __vsock_bind_connectible of af_vsock.c, there is a possible way to achieve code execution due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

View original source
Open Source Vulnerabilities CVE-2025-38618

In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It is possible for a vsock to autobind to VMADDR_PORT_ANY. This can cause a use-after-free when a connection is made to the bound socket. The socket returned by accept() also has port VMADDR_PORT_ANY but is not on the list of unbound sockets. Binding it will result in an extra refcount decrement similar to the one fixed in fcdd2242c023 (vsock: Keep the binding until socket destruction). Modify the check in __vsock_bind_connectible() to also prevent binding to VMADDR_PORT_ANY.

View original source

05 / REFERENCES

Further evidence