CVE-2025-21756 is a use-after-free vulnerability in the Linux kernel's vsock subsystem caused by incorrect socket-binding lifecycle and reference-count handling during transport reassignment. The transport release path calls vsock_remove_bound() without checking whether the socket has moved to the bound list. A subsequent vsock_bind() operation assumes the socket remains in the unbound list and calls __vsock_remove_bound(), which drops the reference count to zero through sock_put(). Subsequent operations access the freed socket in __vsock_bind(). The failure produces slab-use-after-free diagnostics and reference-count addition-on-zero and underflow warnings. The fix preserves both explicit bind() bindings and implicit autobind bindings created during connect() until socket destruction.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains a comprehensive exploit toolkit for CVE-2025-21756, a use-after-free (UAF) vulnerability in the Linux kernel's vsock subsystem. The exploit is designed for local privilege escalation and is operational, providing a working payload that spawns a root shell or executes arbitrary commands as root. The repository is structured with multiple C source files, including several variants and backup versions of the exploit, as well as supporting scripts for building, running, and debugging the exploit in a QEMU virtualized environment. Key files include: - `exploit.c`: The main exploit, which performs heap manipulation and ROP chain construction to escalate privileges. It includes a modprobe-based payload for code execution. - `test.c`, `trigger.c`, `trigger2.c`: Variants and helpers for triggering the UAF and testing different exploitation strategies. - `theori/exploit.c` and `theori/modules/`: An alternative exploit implementation with modularized heap spraying and kernel object manipulation utilities. - Supporting scripts (`compile.sh`, `run.sh`, `local_runner.sh`, etc.) automate building and running the exploit in a controlled environment. The exploit works by manipulating vsock sockets to trigger a UAF, then performing heap spraying (using pipes, UNIX sockets, xattrs, keyrings, etc.) to control freed memory and execute a ROP chain in the kernel. The payload typically calls `commit_creds(init_cred)` to gain root, then spawns a shell or overwrites `/proc/sys/kernel/core_pattern` to execute arbitrary code via modprobe. The exploit is highly configurable and includes utilities for KASLR bypass and kernel address discovery. Fingerprintable endpoints include several file paths used for payload delivery and privilege escalation, such as `/proc/sys/kernel/core_pattern`, `/tmp/evil`, `/tmp/trigger`, and `/proc/1/ns/*` for namespace manipulation. The attack vector is local, requiring the attacker to execute code on the target system. Overall, this repository demonstrates a mature, operational exploit for a modern Linux kernel vulnerability, with extensive support for debugging, testing, and adapting the exploit to different environments.
This repository contains a full exploit environment for CVE-2025-21756, a use-after-free vulnerability in the Linux kernel vsock subsystem. The main exploit logic is implemented in 'x.c', which orchestrates a series of vsock socket operations to trigger the vulnerability, leak kernel addresses, and construct a ROP chain to escalate privileges to root. The payload ultimately spawns a root shell. The repository includes scripts for compiling the exploit ('compress.sh'), extracting kernel images ('extract-image.sh'), and running the exploit in a QEMU virtual machine ('run.sh'). The initramfs directory provides a minimal root filesystem with busybox and necessary symlinks for the QEMU environment. The exploit is operational and targets Linux kernel 6.6.75, requiring vsock support and a controlled VM environment. No network endpoints are directly targeted; the attack vector is local privilege escalation via kernel exploitation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A use-after-free vulnerability in the Linux kernel's vsock implementation. Incorrect binding and reference-count handling during transport reassignment can prematurely free a socket and cause subsequent access to freed memory. The reference assigns a CVSS v3 base score of 7.8, indicating local exploitation requiring low privileges, with high confidentiality, integrity, and availability impacts. Exploits and a security update are available.
A Linux kernel vsock use-after-free vulnerability caused by incorrect socket binding and reference-count handling during transport reassignment. The advisory identifies affected Google COS kernel packages and assigns a CVSS v3 base score of 7.8, with local access and low privileges required. The fix preserves socket bindings until socket destruction.
A Linux kernel vsock use-after-free vulnerability caused by improper preservation of explicit and implicit socket bindings during transport reassignment. The issue can result in reference-count underflow and use-after-free during socket binding operations.
A high-severity Linux kernel vsock use-after-free vulnerability caused by improper preservation of socket bindings during transport reassignment. It can lead to refcount underflow and use-after-free conditions when binding a vsock socket.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.