CVE-2025-21726Use After Free in Linux

CWE-416Use After Free70 documents6 sources
Severity
7.8HIGHNVD
OSV8.8OSV7.1OSV5.9OSV5.5
EPSS
0.0%
top 92.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 27
Latest updateMar 4

Description

In the Linux kernel, the following vulnerability has been resolved: padata: avoid UAF for reorder_work Although the previous patch can avoid ps and ps UAF for _do_serial, it can not avoid potential UAF issue for reorder_work. This issue can happen just as below: crypto_request crypto_request crypto_del_alg padata_do_serial ... padata_reorder // processes all remaining // requests then breaks while (1) { if (!padata) break; ... } padata_do_serial // new request added list_add // sees the new

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

NVDlinux/linux_kernel5.4.195.5+6
Debianlinux/linux_kernel< 5.10.237-1+3
Ubuntulinux/linux_kernel< 5.15.0-140.150+2
CVEListV5linux/linuxbbefa1dd6a6d53537c11624752219e39959d04fbf4f1b1169fc3694f9bc3e28c6c68dbbf4cc744c0+9
debiandebian/linux< linux 6.1.129-1 (bookworm)

Patches

🔴Vulnerability Details

34
OSV
linux-raspi, linux-raspi-5.4 vulnerabilities2026-03-03
OSV
linux-azure, linux-azure-5.4, linux-azure-fips vulnerabilities2026-02-20
OSV
linux-oracle, linux-oracle-5.4 vulnerabilities2026-02-12
OSV
linux-xilinx-zynqmp vulnerabilities2026-02-11
OSV
linux-aws-fips, linux-fips, linux-gcp-fips vulnerabilities2026-01-30

📋Vendor Advisories

35
Ubuntu
Kernel Live Patch Security Notice2026-03-04
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2026-03-03
Ubuntu
Linux kernel (Azure) vulnerabilities2026-02-20
Ubuntu
Linux kernel (Oracle) vulnerabilities2026-02-12
Ubuntu
Linux kernel (Xilinx ZynqMP) vulnerabilities2026-02-11
CVE-2025-21726 — Use After Free in Linux | cvebase