PT-2025-11011 · Linux+5 · Linux Kernel+5

Andi Shyti

+3

·

Publicado

2025-01-16

·

Atualizado

2025-07-16

·

CVE-2025-21849

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel (affected versions not specified)
Description: The issue concerns the use of spin lock/unlock() functions in interrupt contexts, which could result in a deadlock when an interrupt occurs while holding a lock, as seen in GitLab issue #13399. To address this, the solution involves saving the irq state before spin lock acquisition, using spin lock irqsave() in interruptible contexts, and adding irqs' state save/restore calls to all locks/unlocks in signal irq work() execution.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Locking

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2025-4807
BDU:2025-12263
CVE-2025-21849
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
USN-7521-1
USN-7521-2
USN-7521-3

Produtos afetados

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu