- Sources: primary, discussion
- Summary: The post walks a race in the Linux kernel AF_ALG socket interface. The expression the merge path relies on is correct only while the last scatter-gather list holds at least one entry, and the writeup shows two writers plus a failing copy can leave that list empty with the merge flag still set, so the kernel reads
sg[-1] and the preceding heap object supplies an arbitrary write, used here to overwrite core_pattern. On affected range the post states the vulnerable code had been present in Linux since around 2011, and that the analysis and exploit target was v6.12.44. The CVE is from 2025 and the upstream fix prevents concurrent writes to the same AF_ALG socket, but the post names no fixed stable versions and no distribution backports, so a reader cannot tell from it whether a given running kernel carries the fix. - Why it matters: The durable value is the state-machine review pattern and the reach of the escape, since the same primitive crosses out of a Docker container to root on the host.
send feedback on this story