{"id":"CVE-2025-22111","title":"net: Remove RTNL dance for SIOCBRADDIF and SIOCBRDELIF.","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: Remove RTNL dance for SIOCBRADDIF and SIOCBRDELIF.\n\nSIOCBRDELIF is passed to dev_ioctl() first and later forwarded to\nbr_ioctl_call(), which causes unnecessary RTN…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 893b195875340cb44b54c9db99e708145f1210e8 < f51e471cb1577d510c3096e126678e1ea20d2efd","Linux >= 893b195875340cb44b54c9db99e708145f1210e8 < 338a0f3c66aef4ee13052880d02200aae8f2d8a8","Linux >= 893b195875340cb44b54c9db99e708145f1210e8 < d767ce15045df510f55cdd2af5df0eee71f928d0","Linux >= 893b195875340cb44b54c9db99e708145f1210e8 < 4888e1dcc341e9a132ef7b8516234b3c3296de56","Linux >= 893b195875340cb44b54c9db99e708145f1210e8 < 00fe0ac64efd1f5373b3dd9f1f84b19235371e39","Linux >= 893b195875340cb44b54c9db99e708145f1210e8 < ed3ba9b6e280e14cc3148c1b226ba453f02fa76c","Linux 5.15"],"published":"2025-04-16","updated":"2026-09-08","sourceUpdated":"2026-09-08T08:41:22.144Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2025-22111","references":[{"url":"https://git.kernel.org/stable/c/f51e471cb1577d510c3096e126678e1ea20d2efd"},{"url":"https://git.kernel.org/stable/c/338a0f3c66aef4ee13052880d02200aae8f2d8a8"},{"url":"https://git.kernel.org/stable/c/d767ce15045df510f55cdd2af5df0eee71f928d0"},{"url":"https://git.kernel.org/stable/c/4888e1dcc341e9a132ef7b8516234b3c3296de56"},{"url":"https://git.kernel.org/stable/c/00fe0ac64efd1f5373b3dd9f1f84b19235371e39"},{"url":"https://git.kernel.org/stable/c/ed3ba9b6e280e14cc3148c1b226ba453f02fa76c"}],"tags":["cve.org"],"epss":0.00205,"epssPercentile":0.10877,"ingestedAt":"2026-09-08T15:33:26.998Z","slug":"CVE-2025-22111","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: Remove RTNL dance for SIOCBRADDIF and SIOCBRDELIF.\n\nSIOCBRDELIF is passed to dev_ioctl() first and later forwarded to\nbr_ioctl_call(), which causes unnecessary RTNL dance and the splat\nbelow [0] under RTNL pressure.\n\nLet's say Thread A is trying to detach a device from a bridge and\nThread B is trying to remove the bridge.\n\nIn dev_ioctl(), Thread A bumps the bridge device's refcnt by\nnetdev_hold() and releases RTNL because the following br_ioctl_call()\nalso re-acquires RTNL.\n\nIn the race window, Thread B could acquire RTNL and try to remove\nthe bridge device.  Then, rtnl_unlock() by Thread B will release RTNL\nand wait for netdev_put() by Thread A.\n\nThread A, however, must hold RTNL after the unlock in dev_ifsioc(),\nwhich may take long under RTNL pressure, resulting in the splat by\nThread B.\n\n  Thread A (SIOCBRDELIF)           Thread B (SIOCBRDELBR)\n  ----------------------           ----------------------\n  sock_ioctl                       sock_ioctl\n  `- sock_do_ioctl                 `- br_ioctl_call\n     `- dev_ioctl                     `- br_ioctl_stub\n        |- rtnl_lock                     |\n        |- dev_ifsioc                    '\n        '  |- dev = __dev_get_by_name(...)\n           |- netdev_hold(dev, ...)      .\n       /   |- rtnl_unlock  ------.       |\n       |   |- br_ioctl_call       `--->  |- rtnl_lock\n  Race |   |  `- br_ioctl_stub           |- br_del_bridge\n  Window   |     |                       |  |- dev = __dev_get_by_name(...)\n       |   |     |  May take long        |  `- br_dev_delete(dev, ...)\n       |   |     |  under RTNL pressure  |     `- unregister_netdevice_queue(dev, ...)\n       |   |     |               |       `- rtnl_unlock\n       \\   |     |- rtnl_lock  <-'          `- netdev_run_todo\n           |     |- ...                        `- netdev_run_todo\n           |     `- rtnl_unlock                   |- __rtnl_unlock\n           |                                      |- netdev_wait_allrefs_any\n           |- netdev_put(dev, ...)  <----------------'\n                                                Wait refcnt decrement\n                                                and log splat below\n\nTo avoid blocking SIOCBRDELBR unnecessarily, let's not call\ndev_ioctl() for SIOCBRADDIF and SIOCBRDELIF.\n\nIn the dev_ioctl() path, we do the following:\n\n  1. Copy struct ifreq by get_user_ifreq in sock_do_ioctl()\n  2. Check CAP_NET_ADMIN in dev_ioctl()\n  3. Call dev_load() in dev_ioctl()\n  4. Fetch the master dev from ifr.ifr_name in dev_ifsioc()\n\n3. can be done by request_module() in br_ioctl_call(), so we move\n1., 2., and 4. to br_ioctl_stub().\n\nNote that 2. is also checked later in add_del_if(), but it's better\nperformed before RTNL.\n\nSIOCBRADDIF and SIOCBRDELIF have been processed in dev_ioctl() since\nthe pre-git era, and there seems to be no specific reason to process\nthem there.\n\n[0]:\nunregister_netdevice: waiting for wpan3 to become free. Usage count = 2\nref_tracker: wpan3@ffff8880662d8608 has 1/1 users at\n     __netdev_tracker_alloc include/linux/netdevice.h:4282 [inline]\n     netdev_hold include/linux/netdevice.h:4311 [inline]\n     dev_ifsioc+0xc6a/0x1160 net/core/dev_ioctl.c:624\n     dev_ioctl+0x255/0x10c0 net/core/dev_ioctl.c:826\n     sock_do_ioctl+0x1ca/0x260 net/socket.c:1213\n     sock_ioctl+0x23a/0x6c0 net/socket.c:1318\n     vfs_ioctl fs/ioctl.c:51 [inline]\n     __do_sys_ioctl fs/ioctl.c:906 [inline]\n     __se_sys_ioctl fs/ioctl.c:892 [inline]\n     __x64_sys_ioctl+0x1a4/0x210 fs/ioctl.c:892\n     do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n     do_syscall_64+0xcb/0x250 arch/x86/entry/common.c:83\n     entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n## Affected\n\n- `Linux >= 893b195875340cb44b54c9db99e708145f1210e8 < f51e471cb1577d510c3096e126678e1ea20d2efd`\n- `Linux >= 893b195875340cb44b54c9db99e708145f1210e8 < 338a0f3c66aef4ee13052880d02200aae8f2d8a8`\n- `Linux >= 893b195875340cb44b54c9db99e708145f1210e8 < d767ce15045df510f55cdd2af5df0eee71f928d0`\n- `Linux >= 893b195875340cb44b54c9db99e708145f1210e8 < 4888e1dcc341e9a132ef7b8516234b3c3296de56`\n- `Linux >= 893b195875340cb44b54c9db99e708145f1210e8 < 00fe0ac64efd1f5373b3dd9f1f84b19235371e39`\n- `Linux >= 893b195875340cb44b54c9db99e708145f1210e8 < ed3ba9b6e280e14cc3148c1b226ba453f02fa76c`\n- `Linux 5.15`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}