CVE-2025-1290
CVSS 3.1 Score 8.1 of 10 (high)
Details
Published Apr 17, 2025
CWE ID 416
Summary
CVE-2025-1290: A critical race condition Use-After-Free vulnerability has been identified in the virtio_transport_space_update function of Kernel 5.4 on ChromeOS. This vulnerability arises when the virtio_vsock_sock structure is concurrently allocated and freed during an AF_VSOCK connect syscall. The result is a dangling pointer, which can potentially allow an attacker to execute kernel code with elevated privileges. This issue poses a significant risk to the affected systems and requires immediate attention and patching.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Google Chrome OS