CVE-2025-21726
Published: Feb 27, 2025
Modified: May 23, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: padata: avoid UAF for reorder_work Although the previous patch can avoid ps and ps UAF for _do_serial, it can not avoid potential UAF issue for reorder_work. This issue can happen just as below: crypto_request crypto_request crypto_del_alg padata_do_serial ... padata_reorder // processes all remaining // requests then breaks while (1) { if (!padata) break; ... } padata_do_serial // new request added list_add // sees the new request queue_work(reorder_work) padata_reorder queue_work_on(squeue->work) ... <kworker context> padata_serial_worker // completes new request, // no more outstanding // requests crypto_del_alg // free pd <kworker context> invoke_padata_reorder // UAF of pd To avoid UAF for 'reorder_work', get 'pd' ref before put 'reorder_work' into the 'serial_wq' and put 'pd' ref until the 'serial_wq' finish.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected bbefa1dd6a6d53537c11624752219e39959d04fb - < f4f1b1169fc3694f9bc3e28c6c68dbbf4cc744c0affected bbefa1dd6a6d53537c11624752219e39959d04fb - < 4c6209efea2208597dbd3e52dc87a0d1a8f2dbe1affected bbefa1dd6a6d53537c11624752219e39959d04fb - < 7000507bb0d2ceb545c0a690e0c707c897d102c2affected bbefa1dd6a6d53537c11624752219e39959d04fb - < 6f45ef616775b0ce7889b0f6077fc8d681ab30bcaffected bbefa1dd6a6d53537c11624752219e39959d04fb - < 8ca38d0ca8c3d30dd18d311f1a7ec5cb56972cac+6 more versions |
Linux | Linux | affected 5.6unaffected 0 - < 5.6unaffected 5.10.235 - <= 5.10.*unaffected 5.15.179 - <= 5.15.*unaffected 6.1.129 - <= 6.1.*+4 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now