PT-2025-6064 · Linux +5 · Linux Kernel +5

Sudheendra Raghav Neela

·

Published

2025-01-21

·

Updated

2025-11-12

·

CVE-2025-21691

CVSS v2.0
6.2
VectorAV:L/AC:L/Au:S/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, related to the
cachestat()
system call. The issue arose when
cachestat()
was added as a more convenient and performant version of
mincore()
, but it missed a fix for checking writability or ownership. This fix, initially applied to
mincore()
in a previous commit, has now been added to
cachestat()
with modifications for the file context.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Authorization

Weakness Enumeration

Related Identifiers

ALSA-2025:20095
BDU:2025-01800
CVE-2025-21691
INFSA-2025_20518
MGASA-2025-0078
MGASA-2025-0079
OESA-2025-1371
OESA-2025-1372
RHSA-2025:20518
RHSA-2025_20518
USN-7445-1
USN-7448-1
USN-7595-1
USN-7595-2
USN-7595-3
USN-7595-4
USN-7595-5
USN-7596-1
USN-7596-2
USN-7653-1

Affected Products

Almalinux
Astra Linux
Linuxmint
Linux Kernel
Red Hat
Ubuntu