PT-2025-14346 · Linux+2 · Linux Kernel+2

Published

2025-03-03

·

Updated

2026-01-20

·

CVE-2025-21965

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A kernel crash can occur if a BPF scheduler provides an invalid CPU as prev cpu to the scx bpf select cpu dfl() function. This issue is resolved by validating prev cpu in scx bpf select cpu dfl() and triggering an scx error if an invalid CPU is specified.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-11803
CVE-2025-21965

Affected Products

Astra Linux
Linux Kernel
Red Os