Answer in brief
CVE-2025-38618 records a Unknown severity vulnerability in vsock: Do not allow binding to VMADDR_PORT_ANY. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-38618 records a Unknown severity vulnerability in vsock: Do not allow binding to VMADDR_PORT_ANY. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d021c344051af91f42c5ba9fdedc176740cbd238 <c04a2c1ca25b9b23104124d3b2d349d934e302de || >=d021c344051af91f42c5ba9fdedc176740cbd238 <d1a5b1964cef42727668ac0d8532dae4f8c19386 || >=d021c344051af91f42c5ba9fdedc176740cbd238 <cf86704798c1b9c46fa59dfc2d662f57d1394d79 || >=d021c344051af91f42c5ba9fdedc176740cbd238 <f138be5d7f301fddad4e65ec66dfc3ceebf79be3 || >=d021c344051af91f42c5ba9fdedc176740cbd238 <44bd006d5c93f6a8f28b106cbae2428c5d0275b7 || >=d021c344051af91f42c5ba9fdedc176740cbd238 <32950b1907919be86a7a2697d6f93d57068b3865 || >=d021c344051af91f42c5ba9fdedc176740cbd238 <8f01093646b49f6330bb2d36761983fd829472b1 || >=d021c344051af91f42c5ba9fdedc176740cbd238 <d73960f0cf03ef1dc9e96ec7a20e538accc26d87 || >=d021c344051af91f42c5ba9fdedc176740cbd238 <aba0c94f61ec05315fa7815d21aefa4c87f6a9f4 | c04a2c1ca25b9b23104124d3b2d349d934e302de, d1a5b1964cef42727668ac0d8532dae4f8c19386, cf86704798c1b9c46fa59dfc2d662f57d1394d79, f138be5d7f301fddad4e65ec66dfc3ceebf79be3, 44bd006d5c93f6a8f28b106cbae2428c5d0275b7, 32950b1907919be86a7a2697d6f93d57068b3865, 8f01093646b49f6330bb2d36761983fd829472b1, d73960f0cf03ef1dc9e96ec7a20e538accc26d87, aba0c94f61ec05315fa7815d21aefa4c87f6a9f4 |
| Linux/Linuxgeneric | 3.9 | Not reported |
Published upstream
Aug 22, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It is possible for a vsock to autobind to VMADDR_PORT_ANY. This can cause a use-after-free when a connection is made to the bound socket. The socket returned by accept() also has port VMADDR_PORT_ANY but is not on the list of unbound sockets. Binding it will result in an extra refcount decrement similar to the one fixed in fcdd2242c023 (vsock: Keep the binding until socket destruction). Modify the check in __vsock_bind_connectible() to also prevent binding to VMADDR_PORT_ANY.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d021c344051af91f42c5ba9fdedc176740cbd238 <c04a2c1ca25b9b23104124d3b2d349d934e302de || >=d021c344051af91f42c5ba9fdedc176740cbd238 <d1a5b1964cef42727668ac0d8532dae4f8c19386 || >=d021c344051af91f42c5ba9fdedc176740cbd238 <cf86704798c1b9c46fa59dfc2d662f57d1394d79 || >=d021c344051af91f42c5ba9fdedc176740cbd238 <f138be5d7f301fddad4e65ec66dfc3ceebf79be3 || >=d021c344051af91f42c5ba9fdedc176740cbd238 <44bd006d5c93f6a8f28b106cbae2428c5d0275b7 || >=d021c344051af91f42c5ba9fdedc176740cbd238 <32950b1907919be86a7a2697d6f93d57068b3865 || >=d021c344051af91f42c5ba9fdedc176740cbd238 <8f01093646b49f6330bb2d36761983fd829472b1 || >=d021c344051af91f42c5ba9fdedc176740cbd238 <d73960f0cf03ef1dc9e96ec7a20e538accc26d87 || >=d021c344051af91f42c5ba9fdedc176740cbd238 <aba0c94f61ec05315fa7815d21aefa4c87f6a9f4 | c04a2c1ca25b9b23104124d3b2d349d934e302de, d1a5b1964cef42727668ac0d8532dae4f8c19386, cf86704798c1b9c46fa59dfc2d662f57d1394d79, f138be5d7f301fddad4e65ec66dfc3ceebf79be3, 44bd006d5c93f6a8f28b106cbae2428c5d0275b7, 32950b1907919be86a7a2697d6f93d57068b3865, 8f01093646b49f6330bb2d36761983fd829472b1, d73960f0cf03ef1dc9e96ec7a20e538accc26d87, aba0c94f61ec05315fa7815d21aefa4c87f6a9f4 |
| Linux/Linuxgeneric | 3.9 | Not reported |
Published upstream
Aug 22, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: vsock: Do not allow binding to VMADDR_PORT_ANY It is possible for a vsock to autobind to VMADDR_PORT_ANY. This can cause a use-after-free when a connection is made to the bound socket. The socket returned by accept() also has port VMADDR_PORT_ANY but is not on the list of unbound sockets. Binding it will result in an extra refcount decrement similar to the one fixed in fcdd2242c023 (vsock: Keep the binding until socket destruction). Modify the check in __vsock_bind_connectible() to also prevent binding to VMADDR_PORT_ANY.
Quoted source text, attributed separately from HOL analysis.