In ethnlopsbegin of netlink.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"types": [
"EoP"
],
"severity": "High",
"spl": "2025-09-05",
"vanir_signatures": [
{
"source": "https://android.googlesource.com/kernel/common/+/cdd207534a0c4a4f2e4684b90794924a0550e66d",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"172231033618138296802010778550905766852",
"152295685349910418206590432446842144765",
"87806915282566257460123354657461228025",
"297562863665192147190683885644416352543"
]
},
"target": {
"file": "net/ethtool/netlink.c"
},
"id": "ASB-A-392852041-c46d14cb",
"deprecated": false,
"signature_type": "Line"
},
{
"source": "https://android.googlesource.com/kernel/common/+/2afd0800a730081c941189e3174ed0a30f4c59e7",
"signature_version": "v1",
"digest": {
"function_hash": "257543006366309202372562986636404430770",
"length": 468.0
},
"target": {
"function": "ethnl_ops_begin",
"file": "net/ethtool/netlink.c"
},
"id": "ASB-A-392852041-d39e11ac",
"deprecated": false,
"signature_type": "Function"
},
{
"source": "https://android.googlesource.com/kernel/common/+/2afd0800a730081c941189e3174ed0a30f4c59e7",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"172231033618138296802010778550905766852",
"152295685349910418206590432446842144765",
"87806915282566257460123354657461228025",
"297562863665192147190683885644416352543"
]
},
"target": {
"file": "net/ethtool/netlink.c"
},
"id": "ASB-A-392852041-e2bd069b",
"deprecated": false,
"signature_type": "Line"
},
{
"source": "https://android.googlesource.com/kernel/common/+/cdd207534a0c4a4f2e4684b90794924a0550e66d",
"signature_version": "v1",
"digest": {
"function_hash": "257543006366309202372562986636404430770",
"length": 468.0
},
"target": {
"function": "ethnl_ops_begin",
"file": "net/ethtool/netlink.c"
},
"id": "ASB-A-392852041-e38362a0",
"deprecated": false,
"signature_type": "Function"
}
],
"fixes": [
"https://android.googlesource.com/kernel/common/+/cdd207534a0c4a4f2e4684b90794924a0550e66d",
"https://android.googlesource.com/kernel/common/+/2afd0800a730081c941189e3174ed0a30f4c59e7"
]
}