CVE-2025-21671

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-21671
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21671.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-21671
Downstream
Related
Published
2025-01-31T11:25:34.546Z
Modified
2025-12-02T04:03:39.770160Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
zram: fix potential UAF of zram table
Details

In the Linux kernel, the following vulnerability has been resolved:

zram: fix potential UAF of zram table

If zrammetaalloc failed early, it frees allocated zram->table without setting it NULL. Which will potentially cause zrammetafree to access the table if user reset an failed and uninitialized device.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21671.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ac3b5366b9b7c9d97b606532ceab43d2329a22f3
Fixed
fe3de867f94819ba0f28e035c0b0182150147d95
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0b5b0b65561b34e6e360de317e4bcd031bfabf42
Fixed
571d3f6045cd3a6d9f6aec33b678f3ffe97582ef
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6fb92e9a52e3feae309a213950f21dfcd1eb0b40
Fixed
902ef8f16d5ca77edc77c30656be54186c1e99b7
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
74363ec674cb172d8856de25776c8f3103f05e2f
Fixed
212fe1c0df4a150fb6298db2cfff267ceaba5402

Affected versions

v6.*

v6.1.122
v6.1.123
v6.1.124
v6.1.125
v6.1.126
v6.12.10
v6.12.7
v6.12.8
v6.12.9
v6.13-rc4
v6.13-rc5
v6.13-rc6
v6.6.68
v6.6.69
v6.6.70
v6.6.71
v6.6.72
v6.6.73

Database specific

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21671.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.1.122
Fixed
6.1.127
Type
ECOSYSTEM
Events
Introduced
6.6.68
Fixed
6.6.74
Type
ECOSYSTEM
Events
Introduced
6.12.7
Fixed
6.12.11

Database specific

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21671.json"