PT-2025-8795 · Linux+5 · Linux Kernel+5

Harshit Mogalapalli

·

Published

2025-01-24

·

Updated

2026-05-26

·

CVE-2025-21712

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A synchronization issue in the Linux kernel's md-bitmap component can cause a general protection fault, leading to a kernel crash. The problem occurs when the bitmap get stats() function is called while the bitmap is being destroyed or not fully initialized, resulting in a dereference of an invalid bitmap pointer. This issue was exacerbated by a previous commit that started dereferencing bitmap->storage, making the problem easier to trigger.
Recommendations To resolve this issue, protect the bitmap get stats() function with bitmap info.mutex to prevent concurrent access and potential crashes. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-68763
BDU:2025-11948
CVE-2025-21712
DLA-4193-1
DSA-5900-1
ECHO-6B0D-4879-6E28
OESA-2025-1446
OESA-2025-1450
USN-7521-1
USN-7521-2
USN-7521-3
USN-7703-1
USN-7703-2
USN-7703-3
USN-7703-4
USN-7719-1
USN-7737-1

Affected Products

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu