PT-2025-13221 · Linux+4 · Linux Kernel+4

Published

2025-02-20

·

Updated

2026-04-20

·

CVE-2025-21884

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue concerns the lifetime of kernel sockets in the Linux kernel. When kernel sockets are dismantled during the exit of pernet operations, their freeing can be delayed due to any tx packets still held in qdisc or device queues. This triggers a warning from ref tracker dir exit. To fix this, a reference on net->passive is ensured for kernel sockets. A helper, sk net refcnt upgrade, is added for when a kernel socket is converted to a refcounted one.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Weakness Enumeration

Related Identifiers

AZL-62830
BDU:2025-03677
CVE-2025-21884
OESA-2025-1959
OESA-2025-1960
OESA-2025-1961
OPENSUSE-SU-2025_01614-1
OPENSUSE-SU-2025_01707-1
SUSE-SU-2025:01614-1
SUSE-SU-2025:01707-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20206-1
SUSE-SU-2025:20270-1
SUSE-SU-2025:20283-1
SUSE-SU-2025_01614-1
SUSE-SU-2025_01707-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01967-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu