CVE-2025-21781
Published: Feb 27, 2025
Modified: May 11, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix panic during interface removal Reference counting is used to ensure that batadv_hardif_neigh_node and batadv_hard_iface are not freed before/during batadv_v_elp_throughput_metric_update work is finished. But there isn't a guarantee that the hard if will remain associated with a soft interface up until the work is finished. This fixes a crash triggered by reboot that looks like this: Call trace: batadv_v_mesh_free+0xd0/0x4dc [batman_adv] batadv_v_elp_throughput_metric_update+0x1c/0xa4 process_one_work+0x178/0x398 worker_thread+0x2e8/0x4d0 kthread+0xd8/0xdc ret_from_fork+0x10/0x20 (the batadv_v_mesh_free call is misleading, and does not actually happen) I was able to make the issue happen more reliably by changing hardif_neigh->bat_v.metric_work work to be delayed work. This allowed me to track down and confirm the fix. [[email protected]: prevent entering batadv_v_elp_get_throughput without soft_iface]
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected c833484e5f3872a38fe232c663586069d5ad9645 - < 167422a07096a6006599067c8b55884064fa0b72affected c833484e5f3872a38fe232c663586069d5ad9645 - < ce3f1545bf8fa28bd05ec113679e8e6cd23af577affected c833484e5f3872a38fe232c663586069d5ad9645 - < f0a16c6c79768180333f3e41ce63f32730e3c3afaffected c833484e5f3872a38fe232c663586069d5ad9645 - < 7eb5dd201695645af071592a50026eb780081a72affected c833484e5f3872a38fe232c663586069d5ad9645 - < 072b2787321903287a126c148e8db87dd7ef96fe+3 more versions |
Linux | Linux | affected 4.6unaffected 0 - < 4.6unaffected 5.4.291 - <= 5.4.*unaffected 5.10.235 - <= 5.10.*unaffected 5.15.179 - <= 5.15.*+5 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now