Answer in brief
CVE-2025-21638 records a Unknown severity vulnerability in sctp: sysctl: auth_enable: avoid using current->nsproxy. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-21638 records a Unknown severity vulnerability in sctp: sysctl: auth_enable: avoid using current->nsproxy. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b14878ccb7fac0242db82720b784ab62c467c0dc <cf387cdebfaebae228dfba162f94c567a67610c3 || >=b14878ccb7fac0242db82720b784ab62c467c0dc <dc583e7e5f8515ca489c0df28e4362a70eade382 || >=b14878ccb7fac0242db82720b784ab62c467c0dc <bd2a2939423566c654545fa3e96a656662a0af9e || >=b14878ccb7fac0242db82720b784ab62c467c0dc <1b67030d39f2b00f94ac1f0af11ba6657589e4d3 || >=b14878ccb7fac0242db82720b784ab62c467c0dc <7ec30c54f339c640aa7e49d7e9f7bbed6bd42bf6 || >=b14878ccb7fac0242db82720b784ab62c467c0dc <c184bc621e3cef03ac9ba81a50dda2dae6a21d36 || >=b14878ccb7fac0242db82720b784ab62c467c0dc <15649fd5415eda664ef35780c2013adeb5d9c695 || e5eae4a0511241959498b180fa0df0d4f1b11b9c || 88830f227a1f96e44d82ddfcb0cc81d517ec6dd8 || 3938b0336a93fa5faa242dc9e5823ac69df9e066 || >=3.10.41 <3.11 || >=3.12.21 <3.13 || >=3.14.5 <3.15 | cf387cdebfaebae228dfba162f94c567a67610c3, dc583e7e5f8515ca489c0df28e4362a70eade382, bd2a2939423566c654545fa3e96a656662a0af9e, 1b67030d39f2b00f94ac1f0af11ba6657589e4d3, 7ec30c54f339c640aa7e49d7e9f7bbed6bd42bf6, c184bc621e3cef03ac9ba81a50dda2dae6a21d36, 15649fd5415eda664ef35780c2013adeb5d9c695, 3.11, 3.13, 3.15 |
| Linux/Linuxgeneric | 3.15 | Not reported |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
Published upstream
Jan 19, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: auth_enable: avoid using current->nsproxy As mentioned in a previous commit of this series, using the 'net' structure via 'current' is not recommended for different reasons: - Inconsistency: getting info from the reader's/writer's netns vs only from the opener's netns. - current->nsproxy can be NULL in some cases, resulting in an 'Oops' (null-ptr-deref), e.g. when the current task is exiting, as spotted by syzbot [1] using acct(2). The 'net' structure can be obtained from the table->data using container_of(). Note that table->data could also be used directly, but that would increase the size of this fix, while 'sctp.ctl_sock' still needs to be retrieved from 'net' structure.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=b14878ccb7fac0242db82720b784ab62c467c0dc <cf387cdebfaebae228dfba162f94c567a67610c3 || >=b14878ccb7fac0242db82720b784ab62c467c0dc <dc583e7e5f8515ca489c0df28e4362a70eade382 || >=b14878ccb7fac0242db82720b784ab62c467c0dc <bd2a2939423566c654545fa3e96a656662a0af9e || >=b14878ccb7fac0242db82720b784ab62c467c0dc <1b67030d39f2b00f94ac1f0af11ba6657589e4d3 || >=b14878ccb7fac0242db82720b784ab62c467c0dc <7ec30c54f339c640aa7e49d7e9f7bbed6bd42bf6 || >=b14878ccb7fac0242db82720b784ab62c467c0dc <c184bc621e3cef03ac9ba81a50dda2dae6a21d36 || >=b14878ccb7fac0242db82720b784ab62c467c0dc <15649fd5415eda664ef35780c2013adeb5d9c695 || e5eae4a0511241959498b180fa0df0d4f1b11b9c || 88830f227a1f96e44d82ddfcb0cc81d517ec6dd8 || 3938b0336a93fa5faa242dc9e5823ac69df9e066 || >=3.10.41 <3.11 || >=3.12.21 <3.13 || >=3.14.5 <3.15 | cf387cdebfaebae228dfba162f94c567a67610c3, dc583e7e5f8515ca489c0df28e4362a70eade382, bd2a2939423566c654545fa3e96a656662a0af9e, 1b67030d39f2b00f94ac1f0af11ba6657589e4d3, 7ec30c54f339c640aa7e49d7e9f7bbed6bd42bf6, c184bc621e3cef03ac9ba81a50dda2dae6a21d36, 15649fd5415eda664ef35780c2013adeb5d9c695, 3.11, 3.13, 3.15 |
| Linux/Linuxgeneric | 3.15 | Not reported |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
Published upstream
Jan 19, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: sctp: sysctl: auth_enable: avoid using current->nsproxy As mentioned in a previous commit of this series, using the 'net' structure via 'current' is not recommended for different reasons: - Inconsistency: getting info from the reader's/writer's netns vs only from the opener's netns. - current->nsproxy can be NULL in some cases, resulting in an 'Oops' (null-ptr-deref), e.g. when the current task is exiting, as spotted by syzbot [1] using acct(2). The 'net' structure can be obtained from the table->data using container_of(). Note that table->data could also be used directly, but that would increase the size of this fix, while 'sctp.ctl_sock' still needs to be retrieved from 'net' structure.
Quoted source text, attributed separately from HOL analysis.