PT-2025-13178 · Linux+4 · Linux Kernel+4

Published

2025-02-03

·

Updated

2026-04-20

·

CVE-2025-21869

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel version 6.13.0
Description A vulnerability has been resolved in the Linux kernel related to powerpc/code-patching. The issue involves disabling KASAN reports during patching via temporary mm. A KASAN hit was reported on Talos II with kernel 6.13, indicating a user-memory-access bug in copy to kernel nofault. The vulnerability is related to the use of temporary mm for Radix MMU, which doesn't disable KASAN reports during patching, and the introduction of patch instructions() that uses copy to kernel nofault() to copy several instructions at once.
Recommendations For Linux kernel version 6.13.0, update to a newer version that includes the fix for this issue. As a temporary workaround, consider disabling the patch instructions() function until a patch is available. Restrict access to the vulnerable copy to kernel nofault() function to minimize the risk of exploitation. Avoid using the temporary mm feature in the affected kernel version until the issue is resolved.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03815
CVE-2025-21869
OPENSUSE-SU-2025_1177-1
OPENSUSE-SU-2025_1178-1
OPENSUSE-SU-2025_1180-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:1177-1
SUSE-SU-2025:1178-1
SUSE-SU-2025:1180-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_1177-1
SUSE-SU-2025_1178-1
SUSE-SU-2025_1180-1
USN-7521-1
USN-7521-2
USN-7521-3
USN-7703-1
USN-7703-2
USN-7703-3
USN-7703-4
USN-7719-1
USN-7737-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu