PT-2025-9004 · Linux+3 · Linux Kernel+3

Matt Fleming

·

Published

2025-02-07

·

Updated

2025-05-07

·

CVE-2025-21813

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been identified, related to the timers/migration component. The issue arises from an off-by-one error when connecting a new root to the old root, resulting in the old root not being connected to the new root. This can lead to the system running with more than one top-level idle migrator, defeating its purpose. The problem is caused by the children counter of the new root not being correctly updated, leading to potential overcommit and incorrect initialization of the group mask. Although the issue is harmless in certain scenarios, it can still cause warnings and odd behavior.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2025-11993
CVE-2025-21813
USN-7489-1
USN-7489-2
USN-7491-1
USN-7499-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Ubuntu