CVE-2025-21671
published 2025-01-31CVE-2025-21671: In the Linux kernel, the following vulnerability has been resolved: zram: fix potential UAF of zram table If zram_meta_alloc failed early, it frees allocated…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.6th percentile
In the Linux kernel, the following vulnerability has been resolved:
zram: fix potential UAF of zram table
If zram_meta_alloc failed early, it frees allocated zram->table without
setting it NULL. Which will potentially cause zram_meta_free to access
the table if user reset an failed and uninitialized device.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.1.128-1 (bookworm) | linux 6.1.128-1 (bookworm) |
| debian | linux-6.1 | < linux 6.1.128-1 (bookworm) | linux 6.1.128-1 (bookworm) |
| linux | linux | >= 0b5b0b65561b34e6e360de317e4bcd031bfabf42 < 571d3f6045cd3a6d9f6aec33b678f3ffe97582ef | 571d3f6045cd3a6d9f6aec33b678f3ffe97582ef |
| linux | linux | >= 6.1.122 < 6.1.127 | 6.1.127 |
| linux | linux | >= 6.12.7 < 6.12.11 | 6.12.11 |
| linux | linux | >= 6.6.68 < 6.6.74 | 6.6.74 |
| linux | linux | >= 6fb92e9a52e3feae309a213950f21dfcd1eb0b40 < 902ef8f16d5ca77edc77c30656be54186c1e99b7 | 902ef8f16d5ca77edc77c30656be54186c1e99b7 |
| linux | linux | >= 74363ec674cb172d8856de25776c8f3103f05e2f < 212fe1c0df4a150fb6298db2cfff267ceaba5402 | 212fe1c0df4a150fb6298db2cfff267ceaba5402 |
| linux | linux | >= ac3b5366b9b7c9d97b606532ceab43d2329a22f3 < fe3de867f94819ba0f28e035c0b0182150147d95 | fe3de867f94819ba0f28e035c0b0182150147d95 |
| linux | linux_kernel | >= 0 < 6.1.128-1 | 6.1.128-1 |
| linux | linux_kernel | >= 0 < 6.12.11-1 | 6.12.11-1 |
| linux | linux_kernel | >= 0 < 6.12.11-1 | 6.12.11-1 |
| linux | linux_kernel | >= 6.1.122 < 6.1.127 | 6.1.127 |
| linux | linux_kernel | >= 6.12.7 < 6.12.11 | 6.12.11 |
| linux | linux_kernel | >= 6.6.68 < 6.6.74 | 6.6.74 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: zram: fix potential UAF of zram table
vendor_redhat·2025-01-31·CVSS 7.8
CVE-2025-21671 [HIGH] CWE-416 kernel: zram: fix potential UAF of zram table
kernel: zram: fix potential UAF of zram table
In the Linux kernel, the following vulnerability has been resolved:
zram: fix potential UAF of zram table
If zram_meta_alloc failed early, it frees allocated zram->table without
setting it NULL. Which will potentially cause zram_meta_free to access
the table if user reset an failed and uninitialized device.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 8) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 9) - Affected
Debian
CVE-2025-21671: linux - In the Linux kernel, the following vulnerability has been resolved: zram: fix p...
vendor_debian·2025·CVSS 7.8
CVE-2025-21671 [HIGH] CVE-2025-21671: linux - In the Linux kernel, the following vulnerability has been resolved: zram: fix p...
In the Linux kernel, the following vulnerability has been resolved: zram: fix potential UAF of zram table If zram_meta_alloc failed early, it frees allocated zram->table without setting it NULL. Which will potentially cause zram_meta_free to access the table if user reset an failed and uninitialized device.
Scope: local
bookworm: resolved (fixed in 6.1.128-1)
bullseye: resolved
forky: resolved (fixed in 6.12.11-1)
sid: resolved (fixed in 6.12.11-1)
trixie: resolved (fixed in 6.12.11-1)
OSV
CVE-2025-21671: In the Linux kernel, the following vulnerability has been resolved: zram: fix potential UAF of zram table If zram_meta_alloc failed early, it frees al
osv·2025-01-31·CVSS 7.8
CVE-2025-21671 [HIGH] CVE-2025-21671: In the Linux kernel, the following vulnerability has been resolved: zram: fix potential UAF of zram table If zram_meta_alloc failed early, it frees al
In the Linux kernel, the following vulnerability has been resolved: zram: fix potential UAF of zram table If zram_meta_alloc failed early, it frees allocated zram->table without setting it NULL. Which will potentially cause zram_meta_free to access the table if user reset an failed and uninitialized device.
GHSA
GHSA-7792-f3h4-qxjq: In the Linux kernel, the following vulnerability has been resolved:
zram: fix potential UAF of zram table
If zram_meta_alloc failed early, it frees
ghsa_unreviewed·2025-01-31
CVE-2025-21671 [HIGH] CWE-416 GHSA-7792-f3h4-qxjq: In the Linux kernel, the following vulnerability has been resolved:
zram: fix potential UAF of zram table
If zram_meta_alloc failed early, it frees
In the Linux kernel, the following vulnerability has been resolved:
zram: fix potential UAF of zram table
If zram_meta_alloc failed early, it frees allocated zram->table without
setting it NULL. Which will potentially cause zram_meta_free to access
the table if user reset an failed and uninitialized device.
No detection rules found.
No public exploits indexed.
arXiv
AutoPatch: Multi-Agent Framework for Patching Real-World CVE Vulnerabilities
arxiv_fulltext·2025-11-28
AutoPatch: Multi-Agent Framework for Patching Real-World CVE Vulnerabilities
AutoPatch: Multi-Agent Framework for Patching Real-World CVEs Generated by Outdated LLMs
Minjae Seo^ ,
Wonwoo Choi^ ,
Seungwon Shin,
Myoungsung You
^ Minjae Seo and Wonwoo Choi contributed equally to this work.
M. Seo is with Electronics and Telecommunications Research Institute.
W. Choi is with Agency for Defense Development.
S. Shin is with the School of Electrical Engineering, Korea Advanced Institute of Science and Technology.
M. You is with the School of Electrical and Computer Engineering, University of Seoul. E-mail: [email protected]
## Abstract
Large Language Models (LLMs) have emerged as promising tools in software development, enabling automated code generation and analysis.
However, their knowledge is limited to a fixed cutoff date, making them prone to generating code vulne
Bugzilla
CVE-2025-21671 kernel: zram: fix potential UAF of zram table
bugzilla·2025-01-31·CVSS 7.8
CVE-2025-21671 [HIGH] CVE-2025-21671 kernel: zram: fix potential UAF of zram table
CVE-2025-21671 kernel: zram: fix potential UAF of zram table
In the Linux kernel, the following vulnerability has been resolved:
zram: fix potential UAF of zram table
If zram_meta_alloc failed early, it frees allocated zram->table without
setting it NULL. Which will potentially cause zram_meta_free to access
the table if user reset an failed and uninitialized device.
Discussion:
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2025013159-CVE-2025-21671-c4b0@gregkh/T
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2025:20095 https://access.redhat.com/errata/RHSA-2025:20095
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:20518 https://access.redhat.com/errata/RHSA
https://git.kernel.org/stable/c/212fe1c0df4a150fb6298db2cfff267ceaba5402https://git.kernel.org/stable/c/571d3f6045cd3a6d9f6aec33b678f3ffe97582efhttps://git.kernel.org/stable/c/902ef8f16d5ca77edc77c30656be54186c1e99b7https://git.kernel.org/stable/c/fe3de867f94819ba0f28e035c0b0182150147d95https://lists.debian.org/debian-lts-announce/2025/03/msg00001.html
2025-01-31
Published