CVE-2025-21731

Source
https://cve.org/CVERecord?id=CVE-2025-21731
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21731.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-21731
Downstream
Related
Published
2025-02-27T02:07:35Z
Modified
2026-09-09T03:30:50Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
nbd: don't allow reconnect after disconnect
Details

In the Linux kernel, the following vulnerability has been resolved:

nbd: don't allow reconnect after disconnect

Following process can cause nbd_config UAF:

  1. grab nbd_config temporarily;

  2. nbd_genl_disconnect() flush all recv_work() and release the initial reference:

nbd_genl_disconnect nbd_disconnect_and_put nbd_disconnect flush_workqueue(nbd->recv_workq) if (test_and_clear_bit(NBD_RT_HAS_CONFIG_REF, ...)) nbd_config_put -> due to step 1), reference is still not zero

  1. nbd_genl_reconfigure() queue recv_work() again;

nbd_genl_reconfigure config = nbd_get_config_unlocked(nbd) if (!config) -> succeed if (!test_bit(NBD_RT_BOUND, ...)) -> succeed nbd_reconnect_socket queue_work(nbd->recv_workq, &args->work)

  1. step 1) release the reference;

  2. Finially, recv_work() will trigger UAF:

recv_work nbd_config_put(nbd) -> nbd_config is freed atomic_dec(&config->recv_threads) -> UAF

Fix the problem by clearing NBD_RT_BOUND in nbd_genl_disconnect(), so that nbd_genl_reconfigure() will fail.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21731.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
b7aa3d39385dc2d95899f9e379623fef446a2acd
Fixed
e70a578487a47d7cf058904141e586684d1c3381
Fixed
6bef6222a3f6c7adb6396f77f25a3579d821b09a
Fixed
e3be8862d73cac833e0fb7602636c19c6cb94b11
Fixed
e7343fa33751cb07c1c56b666bf37cfca357130e
Fixed
d208d2c52b652913b5eefc8ca434b0d6b757f68f
Fixed
a8ee6ecde2b7bfb58c8a3afe8a9d2b848f580739
Fixed
9793bd5ae4bdbdb2dde401a3cab94a6bfd05e302
Fixed
844b8cdc681612ff24df62cdefddeab5772fadf1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21731.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.12.0
Fixed
5.4.291
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.235
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.179
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.129
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.76
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.13
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21731.json"