PT-2025-10072 · Linux+1 · Linux Kernel+1
Zhang Rui
·
Published
2025-02-11
·
Updated
2025-03-10
·
CVE-2025-21840
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A segmentation fault issue in the Linux kernel's thermal/netlink component has been resolved. The problem occurred when the intel-lpmd tool, which uses the THERMAL GENL ATTR CPU CAPABILITY attribute, encountered a segmentation fault due to a change in the attribute's raw value. This change was introduced by a commit that added new commands and events for thresholds, affecting existing attributes and potentially causing maintenance burdens for userspace thermal netlink event users.
Recommendations
To resolve the issue, move the newly introduced THERMAL GENL ATTR TZ PREV TEMP attribute to the end of the enum thermal genl attr, ensuring that all existing thermal generic netlink attributes remain unaffected.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel