In the Linux kernel, the following vulnerability has been resolved:
net: rose: lock the socket in rose_bind()
syzbot reported a soft lockup in roseloopbacktimer(), with a repro calling bind() from multiple threads.
rose_bind() must lock the socket to avoid this issue.
[
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"293941362050474305904565724562782763110",
"116356252534893397736120533695841527175",
"14132171694393551073660511236381897219",
"202977359740322087887204372815655432400",
"7877141774017315572391671207155494114",
"181327461975029104394074863746574493210",
"294147506921012938779595394307065612972",
"103005130109500484064620026977936776986",
"48665600791728655823550056406514076360",
"5102250891228423708429093237558828974",
"181699219285073173173426445787969879801",
"95375609723255363003964860093920791314",
"301658624245954792776285117454990969358",
"240620504490901105735756479719234261663",
"15685275452476954894035081573383792123",
"187377552799400678427210254827474636879",
"291611938534163539025731954120156809291",
"237985846758709359539678598513745822119",
"145290798922336803419037045023237006632",
"237881978585560385104063497717369330646"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a1300691aed9ee852b0a9192e29e2bdc2411a7e6",
"target": {
"file": "net/rose/af_rose.c"
},
"id": "CVE-2025-21749-23b85895"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 1444.0,
"function_hash": "117203501710945820329038489870317274588"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@a1300691aed9ee852b0a9192e29e2bdc2411a7e6",
"target": {
"file": "net/rose/af_rose.c",
"function": "rose_bind"
},
"id": "CVE-2025-21749-29f91739"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 1379.0,
"function_hash": "206026319383564030501002819668429542288"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b8bf5c3fb778bbb1f3ff7d98ec577c969f687513",
"target": {
"file": "net/rose/af_rose.c",
"function": "rose_bind"
},
"id": "CVE-2025-21749-30fe8af0"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"293941362050474305904565724562782763110",
"116356252534893397736120533695841527175",
"14132171694393551073660511236381897219",
"202977359740322087887204372815655432400",
"7877141774017315572391671207155494114",
"181327461975029104394074863746574493210",
"294147506921012938779595394307065612972",
"103005130109500484064620026977936776986",
"48665600791728655823550056406514076360",
"5102250891228423708429093237558828974",
"181699219285073173173426445787969879801",
"95375609723255363003964860093920791314",
"301658624245954792776285117454990969358",
"240620504490901105735756479719234261663",
"15685275452476954894035081573383792123",
"187377552799400678427210254827474636879",
"291611938534163539025731954120156809291",
"237985846758709359539678598513745822119",
"145290798922336803419037045023237006632",
"237881978585560385104063497717369330646"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@b8bf5c3fb778bbb1f3ff7d98ec577c969f687513",
"target": {
"file": "net/rose/af_rose.c"
},
"id": "CVE-2025-21749-3fd6a235"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"293941362050474305904565724562782763110",
"116356252534893397736120533695841527175",
"14132171694393551073660511236381897219",
"202977359740322087887204372815655432400",
"7877141774017315572391671207155494114",
"181327461975029104394074863746574493210",
"294147506921012938779595394307065612972",
"103005130109500484064620026977936776986",
"48665600791728655823550056406514076360",
"5102250891228423708429093237558828974",
"181699219285073173173426445787969879801",
"95375609723255363003964860093920791314",
"301658624245954792776285117454990969358",
"240620504490901105735756479719234261663",
"15685275452476954894035081573383792123",
"187377552799400678427210254827474636879",
"291611938534163539025731954120156809291",
"237985846758709359539678598513745822119",
"145290798922336803419037045023237006632",
"237881978585560385104063497717369330646"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4c04b0ab3a647e76d0e752b013de8e404abafc63",
"target": {
"file": "net/rose/af_rose.c"
},
"id": "CVE-2025-21749-53345de7"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 1444.0,
"function_hash": "117203501710945820329038489870317274588"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e0384efd45f615603e6869205b72040c209e69cc",
"target": {
"file": "net/rose/af_rose.c",
"function": "rose_bind"
},
"id": "CVE-2025-21749-5d8c8fb1"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"293941362050474305904565724562782763110",
"116356252534893397736120533695841527175",
"14132171694393551073660511236381897219",
"202977359740322087887204372815655432400",
"7877141774017315572391671207155494114",
"181327461975029104394074863746574493210",
"294147506921012938779595394307065612972",
"103005130109500484064620026977936776986",
"48665600791728655823550056406514076360",
"5102250891228423708429093237558828974",
"181699219285073173173426445787969879801",
"95375609723255363003964860093920791314",
"301658624245954792776285117454990969358",
"240620504490901105735756479719234261663",
"15685275452476954894035081573383792123",
"187377552799400678427210254827474636879",
"291611938534163539025731954120156809291",
"237985846758709359539678598513745822119",
"145290798922336803419037045023237006632",
"237881978585560385104063497717369330646"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d308661a0f4e7c8e86dfc7074a55ee5894c61538",
"target": {
"file": "net/rose/af_rose.c"
},
"id": "CVE-2025-21749-72945c72"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 1444.0,
"function_hash": "117203501710945820329038489870317274588"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@970cd2ed26cdab2b0f15b6d90d7eaa36538244a5",
"target": {
"file": "net/rose/af_rose.c",
"function": "rose_bind"
},
"id": "CVE-2025-21749-736d968f"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 1379.0,
"function_hash": "206026319383564030501002819668429542288"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@d308661a0f4e7c8e86dfc7074a55ee5894c61538",
"target": {
"file": "net/rose/af_rose.c",
"function": "rose_bind"
},
"id": "CVE-2025-21749-7ed25556"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"293941362050474305904565724562782763110",
"116356252534893397736120533695841527175",
"14132171694393551073660511236381897219",
"202977359740322087887204372815655432400",
"7877141774017315572391671207155494114",
"181327461975029104394074863746574493210",
"294147506921012938779595394307065612972",
"103005130109500484064620026977936776986",
"48665600791728655823550056406514076360",
"5102250891228423708429093237558828974",
"181699219285073173173426445787969879801",
"95375609723255363003964860093920791314",
"301658624245954792776285117454990969358",
"240620504490901105735756479719234261663",
"15685275452476954894035081573383792123",
"187377552799400678427210254827474636879",
"291611938534163539025731954120156809291",
"237985846758709359539678598513745822119",
"145290798922336803419037045023237006632",
"237881978585560385104063497717369330646"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e0384efd45f615603e6869205b72040c209e69cc",
"target": {
"file": "net/rose/af_rose.c"
},
"id": "CVE-2025-21749-8d3ac145"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"293941362050474305904565724562782763110",
"116356252534893397736120533695841527175",
"14132171694393551073660511236381897219",
"202977359740322087887204372815655432400",
"7877141774017315572391671207155494114",
"181327461975029104394074863746574493210",
"294147506921012938779595394307065612972",
"103005130109500484064620026977936776986",
"48665600791728655823550056406514076360",
"5102250891228423708429093237558828974",
"181699219285073173173426445787969879801",
"95375609723255363003964860093920791314",
"301658624245954792776285117454990969358",
"240620504490901105735756479719234261663",
"15685275452476954894035081573383792123",
"187377552799400678427210254827474636879",
"291611938534163539025731954120156809291",
"237985846758709359539678598513745822119",
"145290798922336803419037045023237006632",
"237881978585560385104063497717369330646"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@970cd2ed26cdab2b0f15b6d90d7eaa36538244a5",
"target": {
"file": "net/rose/af_rose.c"
},
"id": "CVE-2025-21749-94219de7"
},
{
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"293941362050474305904565724562782763110",
"116356252534893397736120533695841527175",
"14132171694393551073660511236381897219",
"202977359740322087887204372815655432400",
"7877141774017315572391671207155494114",
"181327461975029104394074863746574493210",
"294147506921012938779595394307065612972",
"103005130109500484064620026977936776986",
"48665600791728655823550056406514076360",
"5102250891228423708429093237558828974",
"181699219285073173173426445787969879801",
"95375609723255363003964860093920791314",
"301658624245954792776285117454990969358",
"240620504490901105735756479719234261663",
"15685275452476954894035081573383792123",
"187377552799400678427210254827474636879",
"291611938534163539025731954120156809291",
"237985846758709359539678598513745822119",
"145290798922336803419037045023237006632",
"237881978585560385104063497717369330646"
],
"threshold": 0.9
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@667f61b3498df751c8b3f0be1637e7226cbe3ed0",
"target": {
"file": "net/rose/af_rose.c"
},
"id": "CVE-2025-21749-94998234"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 1444.0,
"function_hash": "117203501710945820329038489870317274588"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4c04b0ab3a647e76d0e752b013de8e404abafc63",
"target": {
"file": "net/rose/af_rose.c",
"function": "rose_bind"
},
"id": "CVE-2025-21749-e7be97c3"
},
{
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"digest": {
"length": 1444.0,
"function_hash": "117203501710945820329038489870317274588"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@667f61b3498df751c8b3f0be1637e7226cbe3ed0",
"target": {
"file": "net/rose/af_rose.c",
"function": "rose_bind"
},
"id": "CVE-2025-21749-efaf494d"
}
]