In the Linux kernel, the following vulnerability has been resolved:
net: atm: fix use after free in lec_send()
The ->send() operation frees skb so save the length before calling ->send() to avoid a use after free.
[
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@82d9084a97892de1ee4881eb5c17911fcd9be6f6",
"id": "CVE-2025-22004-11e6037c",
"deprecated": false,
"target": {
"function": "lec_send",
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"length": 315.0,
"function_hash": "208595964455572661627568011449158528745"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@50e288097c2c6e5f374ae079394436fc29d1e88e",
"id": "CVE-2025-22004-1634171d",
"deprecated": false,
"target": {
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"140982194473456284655577955072550493681",
"296513112958239514169726885400059035930",
"91998384793590248680894217801242958121",
"101231030639658463570172148195867519771",
"114424877148071169618273184066674632442",
"192886805943921531511388394377978637335",
"172351513566906174766989801418389359665",
"6162495171633433451390152712398448676"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@326223182e4703cde99fdbd36d07d0b3de9980fb",
"id": "CVE-2025-22004-1a243829",
"deprecated": false,
"target": {
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"140982194473456284655577955072550493681",
"296513112958239514169726885400059035930",
"91998384793590248680894217801242958121",
"101231030639658463570172148195867519771",
"114424877148071169618273184066674632442",
"192886805943921531511388394377978637335",
"295603384678627133845636799821706377823",
"150621835750863875783135509379152139479"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@51e8be9578a2e74f9983d8fd8de8cafed191f30c",
"id": "CVE-2025-22004-2ebd50db",
"deprecated": false,
"target": {
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"140982194473456284655577955072550493681",
"296513112958239514169726885400059035930",
"91998384793590248680894217801242958121",
"101231030639658463570172148195867519771",
"114424877148071169618273184066674632442",
"192886805943921531511388394377978637335",
"295603384678627133845636799821706377823",
"150621835750863875783135509379152139479"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8cd90c7db08f32829bfa1b5b2b11fbc542afbab7",
"id": "CVE-2025-22004-3239fa29",
"deprecated": false,
"target": {
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"140982194473456284655577955072550493681",
"296513112958239514169726885400059035930",
"91998384793590248680894217801242958121",
"101231030639658463570172148195867519771",
"114424877148071169618273184066674632442",
"192886805943921531511388394377978637335",
"295603384678627133845636799821706377823",
"150621835750863875783135509379152139479"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@82d9084a97892de1ee4881eb5c17911fcd9be6f6",
"id": "CVE-2025-22004-69edf6c2",
"deprecated": false,
"target": {
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"140982194473456284655577955072550493681",
"296513112958239514169726885400059035930",
"91998384793590248680894217801242958121",
"101231030639658463570172148195867519771",
"114424877148071169618273184066674632442",
"192886805943921531511388394377978637335",
"295603384678627133845636799821706377823",
"150621835750863875783135509379152139479"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f3009d0d6ab78053117f8857b921a8237f4d17b3",
"id": "CVE-2025-22004-6a705063",
"deprecated": false,
"target": {
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"140982194473456284655577955072550493681",
"296513112958239514169726885400059035930",
"91998384793590248680894217801242958121",
"101231030639658463570172148195867519771",
"114424877148071169618273184066674632442",
"192886805943921531511388394377978637335",
"295603384678627133845636799821706377823",
"150621835750863875783135509379152139479"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f3009d0d6ab78053117f8857b921a8237f4d17b3",
"id": "CVE-2025-22004-6bb24fa3",
"deprecated": false,
"target": {
"function": "lec_send",
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"length": 315.0,
"function_hash": "208595964455572661627568011449158528745"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@50e288097c2c6e5f374ae079394436fc29d1e88e",
"id": "CVE-2025-22004-7ae079cc",
"deprecated": false,
"target": {
"function": "lec_send",
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"length": 315.0,
"function_hash": "208595964455572661627568011449158528745"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@51e8be9578a2e74f9983d8fd8de8cafed191f30c",
"id": "CVE-2025-22004-90bd2988",
"deprecated": false,
"target": {
"function": "lec_send",
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"length": 315.0,
"function_hash": "208595964455572661627568011449158528745"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9566f6ee13b17a15d0a47667ad1b1893c539f730",
"id": "CVE-2025-22004-ab9a7fae",
"deprecated": false,
"target": {
"function": "lec_send",
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"length": 315.0,
"function_hash": "208595964455572661627568011449158528745"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@9566f6ee13b17a15d0a47667ad1b1893c539f730",
"id": "CVE-2025-22004-b177f9bb",
"deprecated": false,
"target": {
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"140982194473456284655577955072550493681",
"296513112958239514169726885400059035930",
"91998384793590248680894217801242958121",
"101231030639658463570172148195867519771",
"114424877148071169618273184066674632442",
"192886805943921531511388394377978637335",
"295603384678627133845636799821706377823",
"150621835750863875783135509379152139479"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@8cd90c7db08f32829bfa1b5b2b11fbc542afbab7",
"id": "CVE-2025-22004-b4001310",
"deprecated": false,
"target": {
"function": "lec_send",
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"length": 315.0,
"function_hash": "208595964455572661627568011449158528745"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f3271f7548385e0096739965961c7cbf7e6b4762",
"id": "CVE-2025-22004-badbe96e",
"deprecated": false,
"target": {
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"140982194473456284655577955072550493681",
"296513112958239514169726885400059035930",
"91998384793590248680894217801242958121",
"101231030639658463570172148195867519771",
"114424877148071169618273184066674632442",
"192886805943921531511388394377978637335",
"295603384678627133845636799821706377823",
"150621835750863875783135509379152139479"
]
},
"signature_type": "Line"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@326223182e4703cde99fdbd36d07d0b3de9980fb",
"id": "CVE-2025-22004-e42dc519",
"deprecated": false,
"target": {
"function": "lec_send",
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"length": 315.0,
"function_hash": "208595964455572661627568011449158528745"
},
"signature_type": "Function"
},
{
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f3271f7548385e0096739965961c7cbf7e6b4762",
"id": "CVE-2025-22004-ffeee75a",
"deprecated": false,
"target": {
"function": "lec_send",
"file": "net/atm/lec.c"
},
"signature_version": "v1",
"digest": {
"length": 315.0,
"function_hash": "208595964455572661627568011449158528745"
},
"signature_type": "Function"
}
]