CVE Database
/

CVE-2025-21726

Back to search

CVE-2025-21726

Published: Feb 27, 2025

Modified: May 23, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: padata: avoid UAF for reorder_work Although the previous patch can avoid ps and ps UAF for _do_serial, it can not avoid potential UAF issue for reorder_work. This issue can happen just as below: crypto_request crypto_request crypto_del_alg padata_do_serial ... padata_reorder // processes all remaining // requests then breaks while (1) { if (!padata) break; ... } padata_do_serial // new request added list_add // sees the new request queue_work(reorder_work) padata_reorder queue_work_on(squeue->work) ... <kworker context> padata_serial_worker // completes new request, // no more outstanding // requests crypto_del_alg // free pd <kworker context> invoke_padata_reorder // UAF of pd To avoid UAF for 'reorder_work', get 'pd' ref before put 'reorder_work' into the 'serial_wq' and put 'pd' ref until the 'serial_wq' finish.

VendorProductVersions

Linux

Linux

affected
bbefa1dd6a6d53537c11624752219e39959d04fb - < f4f1b1169fc3694f9bc3e28c6c68dbbf4cc744c0
affected
bbefa1dd6a6d53537c11624752219e39959d04fb - < 4c6209efea2208597dbd3e52dc87a0d1a8f2dbe1
affected
bbefa1dd6a6d53537c11624752219e39959d04fb - < 7000507bb0d2ceb545c0a690e0c707c897d102c2
affected
bbefa1dd6a6d53537c11624752219e39959d04fb - < 6f45ef616775b0ce7889b0f6077fc8d681ab30bc
affected
bbefa1dd6a6d53537c11624752219e39959d04fb - < 8ca38d0ca8c3d30dd18d311f1a7ec5cb56972cac

+6 more versions

Linux

Linux

affected
5.6
unaffected
0 - < 5.6
unaffected
5.10.235 - <= 5.10.*
unaffected
5.15.179 - <= 5.15.*
unaffected
6.1.129 - <= 6.1.*

+4 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now