CVE-2025-1290: Use After Free
A race condition Use-After-Free vulnerability exists in the virtiotransportspaceupdate function within the Kernel 5.4 on ChromeOS. Concurrent allocation and freeing of the virtiovsocksock structure during an AFVSOCK connect syscall can occur before a worker thread accesses it resulting in a dangling pointer and potential kernel code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1290?
CVE-2025-1290 is classified as a critical severity vulnerability due to its potential for exploitation in race conditions.
How can CVE-2025-1290 be mitigated?
To mitigate CVE-2025-1290, users should update their ChromeOS to the latest version where the vulnerability has been patched.
What is affected by CVE-2025-1290?
CVE-2025-1290 affects ChromeOS version 5.4 and is specifically related to the virtio_transport_space_update function.
What type of vulnerability is CVE-2025-1290?
CVE-2025-1290 is a race condition Use-After-Free vulnerability impacting the virtio_vsock_sock structure.
What are the consequences of CVE-2025-1290 if exploited?
If exploited, CVE-2025-1290 could lead to unintended access and potential denial of service in the affected ChromeOS systems.