PT-2025-9004 · Linux+3 · Linux Kernel+3

Matt Fleming

·

Publicado

2025-02-07

·

Atualizado

2025-05-07

·

CVE-2025-21813

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been identified, related to the timers/migration component. The issue arises from an off-by-one error when connecting a new root to the old root, resulting in the old root not being connected to the new root. This can lead to the system running with more than one top-level idle migrator, defeating its purpose. The problem is caused by the children counter of the new root not being correctly updated, leading to potential overcommit and incorrect initialization of the group mask. Although the issue is harmless in certain scenarios, it can still cause warnings and odd behavior.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-11993
CVE-2025-21813
USN-7489-1
USN-7489-2
USN-7491-1
USN-7499-1

Produtos afetados

Astra Linux
Linuxmint
Linux Kernel
Ubuntu