PT-2025-10072 · Linux+1 · Linux Kernel+1

Zhang Rui

·

Published

2025-02-11

·

Updated

2025-03-10

·

CVE-2025-21840

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A segmentation fault issue in the Linux kernel's thermal/netlink component has been resolved. The problem occurred when the intel-lpmd tool, which uses the THERMAL GENL ATTR CPU CAPABILITY attribute, encountered a segmentation fault due to a change in the attribute's raw value. This change was introduced by a commit that added new commands and events for thresholds, affecting existing attributes and potentially causing maintenance burdens for userspace thermal netlink event users.
Recommendations To resolve the issue, move the newly introduced THERMAL GENL ATTR TZ PREV TEMP attribute to the end of the enum thermal genl attr, ensuring that all existing thermal generic netlink attributes remain unaffected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-03922
CVE-2025-21840

Affected Products

Astra Linux
Linux Kernel