CVE-2025-21671

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-21671
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21671.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-21671
Downstream
Related
Published
2025-01-31T11:25:34Z
Modified
2025-10-17T21:56:49.708524Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
zram: fix potential UAF of zram table
Details

In the Linux kernel, the following vulnerability has been resolved:

zram: fix potential UAF of zram table

If zrammetaalloc failed early, it frees allocated zram->table without setting it NULL. Which will potentially cause zrammetafree to access the table if user reset an failed and uninitialized device.

References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ac3b5366b9b7c9d97b606532ceab43d2329a22f3
Fixed
fe3de867f94819ba0f28e035c0b0182150147d95
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
0b5b0b65561b34e6e360de317e4bcd031bfabf42
Fixed
571d3f6045cd3a6d9f6aec33b678f3ffe97582ef
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6fb92e9a52e3feae309a213950f21dfcd1eb0b40
Fixed
902ef8f16d5ca77edc77c30656be54186c1e99b7
Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
74363ec674cb172d8856de25776c8f3103f05e2f
Fixed
212fe1c0df4a150fb6298db2cfff267ceaba5402

Affected versions

v6.*

v6.1.122
v6.1.123
v6.1.124
v6.1.125
v6.1.126
v6.12.10
v6.12.7
v6.12.8
v6.12.9
v6.13-rc4
v6.13-rc5
v6.13-rc6
v6.6.68
v6.6.69
v6.6.70
v6.6.71
v6.6.72
v6.6.73

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.1.122
Fixed
6.1.127
Type
ECOSYSTEM
Events
Introduced
6.6.68
Fixed
6.6.74
Type
ECOSYSTEM
Events
Introduced
6.12.7
Fixed
6.12.11