🛡️ AZL-64749 — kernel

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

CVE-2025-38185 affecting package kernel for versions less than 6.6.96.1-1

In the Linux kernel, the following vulnerability has been resolved:

atm: atmtcp: Free invalid length skb in atmtcp_c_send().

syzbot reported the splat below. [0]

vcc_sendmsg() copies data passed from userspace to skb and passes

it to vcc->dev->ops->send().

atmtcp_c_send() accesses skb->data as struct atmtcp_hdr after

checking if skb->len is 0, but it's not enough.

Also, when skb->len == 0, skb and sk (vcc) were leaked because

dev_kfree_skb() is not called and sk_wmem_alloc adjustment is missing

to revert atm_account_tx() in vcc_sendmsg(), which is expected

to be done in atm_pop_raw().

Let's properly free skb with an invalid length in atmtcp_c_send().

[0]:

BUG: KMSAN: uninit-value in atmtcp_c_send+0x255/0xed0 drivers/atm/atmtcp.c:294

atmtcp_c_send+0x255/0xed0 drivers/atm/atmtcp.c:294

vcc_sendmsg+0xd7c/0xff0 net/atm/common.c:644

sock_sendmsg_nosec net/socket.c:712 [inline]

__sock_sendmsg+0x330/0x3d0 net/socket.c:727

____sys_sendmsg+0x7e0/0xd80 net/socket.c:2566

___sys_sendmsg+0x271/0x3b0 net/socket.c:2620

__sys_sendmsg net/socket.c:2652 [inline]

__do_sys_sendmsg net/socket.c:2657 [inline]

__se_sys_sendmsg net/socket.c:2655 [inline]

__x64_sys_sendmsg+0x211/0x3e0 net/socket.c:2655

x64_sys_call+0x32fb/0x3db0 arch/x86/include/generated/asm/syscalls_64.h:47

do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]

do_syscall_64+0xd9/0x210 arch/x86/entry/syscall_64.c:94

entry_SYSCALL_64_after_hwframe+0x77/0x7f

Uninit was created at:

slab_post_alloc_hook mm/slub.c:4154 [inline]

slab_alloc_node mm/slub.c:4197 [inline]

kmem_cache_alloc_node_noprof+0x818/0xf00 mm/slub.c:4249

kmalloc_reserve+0x13c/0x4b0 net/core/skbuff.c:579

__alloc_skb+0x347/0x7d0 net/core/skbuff.c:670

alloc_skb include/linux/skbuff.h:1336 [inline]

vcc_sendmsg+0xb40/0xff0 net/atm/common.c:628

sock_sendmsg_nosec net/socket.c:712 [inline]

__sock_sendmsg+0x330/0x3d0 net/socket.c:727

____sys_sendmsg+0x7e0/0xd80 net/socket.c:2566

___sys_sendmsg+0x271/0x3b0 net/socket.c:2620

__sys_sendmsg net/socket.c:2652 [inline]

__do_sys_sendmsg net/socket.c:2657 [inline]

__se_sys_sendmsg net/socket.c:2655 [inline]

__x64_sys_sendmsg+0x211/0x3e0 net/socket.c:2655

x64_sys_call+0x32fb/0x3db0 arch/x86/include/generated/asm/syscalls_64.h:47

do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]

do_syscall_64+0xd9/0x210 arch/x86/entry/syscall_64.c:94

entry_SYSCALL_64_after_hwframe+0x77/0x7f

CPU: 1 UID: 0 PID: 5798 Comm: syz-executor192 Not tainted 6.16.0-rc1-syzkaller-00010-g2c4a1f3fe03e #0 PREEMPT(undef)

Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 05/07/2025

Affected software

AZL-64749 is recorded against 1 package.

  • kernel (fixed in 6.6.96.1-1)

Timeline and source

Published on 4 July 2025 and last revised on 21 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

nvd.nist.gov (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-07-04
Updated 2026-08-12
Modified 2026-04-21
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 6.6.96.1-1

Similar Threats

Free Vulnerability Check

Is your site affected by AZL-64749?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against AZL-64749 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.