PT-2025-8795 · Linux+5 · Linux Kernel+5
Harshit Mogalapalli
·
Published
2025-01-24
·
Updated
2026-05-26
·
CVE-2025-21712
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A synchronization issue in the Linux kernel's md-bitmap component can cause a general protection fault, leading to a kernel crash. The problem occurs when the
bitmap get stats() function is called while the bitmap is being destroyed or not fully initialized, resulting in a dereference of an invalid bitmap pointer. This issue was exacerbated by a previous commit that started dereferencing bitmap->storage, making the problem easier to trigger.Recommendations
To resolve this issue, protect the
bitmap get stats() function with bitmap info.mutex to prevent concurrent access and potential crashes.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Ubuntu