PT-2025-13224 · Linux+10 · Linux Kernel+10

Published

2025-02-15

·

Updated

2026-04-20

·

CVE-2025-21887

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is caused by a use-after-free error in the ovl dentry update reval function. This error occurs because dput(upper) is called before ovl dentry update reval(), while upper->d flags is still accessed in ovl dentry remote(). To fix this, dput(upper) is moved after its last use. The problem was identified by KASAN, which reported a slab-use-after-free error in ovl dentry remote and ovl dentry update reval.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:10379
ALT-PU-2025-12647
ALT-PU-2025-5786
AZL-59405
BDU:2025-03684
CVE-2025-21887
DLA-4193-1
DLA-4404-1
DSA-5900-1
ECHO-3CA7-701F-2F0A
INFSA-2025_10379
LSN-0114-1
LSN-0115-1
OESA-2025-1371
OESA-2025-1372
OESA-2025-1409
OESA-2025-1410
OPENSUSE-SU-2025_01614-1
OPENSUSE-SU-2025_01707-1
RHSA-2025:10379
RHSA-2025:11810
RHSA-2025:9079
RHSA-2025_10379
SUSE-SU-2025:01614-1
SUSE-SU-2025:01707-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20206-1
SUSE-SU-2025:20270-1
SUSE-SU-2025:20283-1
SUSE-SU-2025_01614-1
SUSE-SU-2025_01707-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01967-1
USN-7510-1
USN-7510-2
USN-7510-3
USN-7510-4
USN-7510-5
USN-7510-6
USN-7510-7
USN-7510-8
USN-7511-1
USN-7511-2
USN-7511-3
USN-7512-1
USN-7521-1
USN-7521-2
USN-7521-3
USN-7593-1
USN-7602-1
USN-7725-1
USN-7725-2
USN-7725-3
USN-7779-1
USN-7802-1
USN-7809-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu