PT-2025-14485 · Linux+1 · Linux Kernel+1
Published
2025-02-20
·
Updated
2026-03-13
·
CVE-2025-21988
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A data corruption issue exists in the Linux kernel's network file system read collect functionality. When multiple subrequests donate data to the same "next" request, depending on the subrequest completion order, each of them overwrites the
prev donated field, causing data corruption and a BUG() crash.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linux Kernel