PT-2025-8801 · Linux+7 · Linux Kernel+7

Syzbot

·

Published

2025-01-22

·

Updated

2026-04-20

·

CVE-2025-21718

CVSS v4.0

7.3

High

VectorAV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.13.0-rc5
Description A vulnerability in the Linux kernel has been resolved, specifically in the Rose protocol implementation. The issue arises from timer races against user threads, where Rose timers only acquire the socket spinlock without checking if the socket is owned by one user thread. This can lead to a slab-use-after-free error. The vulnerability is triggered when the rose timer expiry function is called, which can cause a read of size 2 at an invalid address.
Recommendations For Linux kernel versions prior to 6.13.0-rc5, update to a version that includes the fix for the Rose timer issue, which adds a check and rearms the timers if needed. As a temporary workaround, consider disabling the Rose protocol until a patch is available. Restrict access to the rose timer expiry function to minimize the risk of exploitation. Avoid using the Rose protocol in critical systems until the issue is resolved.

Exploit

Fix

Use After Free

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12647
AZL-57988
BDU:2025-11995
CVE-2025-21718
DLA-4102-1
DLA-4178-1
OESA-2025-1371
OESA-2025-1372
OESA-2025-1409
OESA-2025-1410
OPENSUSE-SU-2025_1177-1
OPENSUSE-SU-2025_1178-1
OPENSUSE-SU-2025_1180-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:0983-1
SUSE-SU-2025:1027-1
SUSE-SU-2025:1176-1
SUSE-SU-2025:1177-1
SUSE-SU-2025:1178-1
SUSE-SU-2025:1180-1
SUSE-SU-2025:1183-1
SUSE-SU-2025:1241-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_0983-1
SUSE-SU-2025_1027-1
SUSE-SU-2025_1177-1
SUSE-SU-2025_1178-1
SUSE-SU-2025_1180-1
SUSE-SU-2025_1241-1
SUSE-SU-2026:0385-1
USN-7510-1
USN-7510-2
USN-7510-3
USN-7510-4
USN-7510-5
USN-7510-6
USN-7510-7
USN-7510-8
USN-7511-1
USN-7511-2
USN-7511-3
USN-7512-1
USN-7516-1
USN-7516-2
USN-7516-3
USN-7516-4
USN-7516-5
USN-7516-6
USN-7516-7
USN-7516-8
USN-7516-9
USN-7517-1
USN-7517-2
USN-7517-3
USN-7518-1
USN-7521-1
USN-7521-2
USN-7521-3
USN-7539-1
USN-7540-1
USN-7593-1
USN-7602-1
USN-7640-1
USN-7651-1
USN-7651-2
USN-7651-3
USN-7651-4
USN-7651-5
USN-7651-6
USN-7652-1
USN-7653-1
USN-7737-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu