CVE-2025-40355

sysfs: check visibility before changing group attribute ownership

References

Notes

 carnil> Introduced in 303a42769c4c ("sysfs: add sysfs_group{s}_change_owner()")
 carnil> 0c17270f9b92 ("net: sysfs: Implement is_visible for phys_(port_id, port_name,
 carnil> switch_id)"). Vulnerable versions: 5.7.

Bugs

Status

Branch Status
upstream released (6.18-rc3) [c7fbb8218b4ad35fec0bd2256d2b9c8d60331f33]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable released (6.17.6) [ac2c526e103285d80a0330b91a318f6c9276d35a]
6.12-upstream-stable needed
6.6-upstream-stable needed
6.1-upstream-stable needed
5.10-upstream-stable needed
sid released (6.17.6-1)
6.12-trixie-security needed
6.1-bookworm-security needed
5.10-bullseye-security needed