cbcvebase.
CVE-2025-21728
published 2025-02-27

CVE-2025-21728: In the Linux kernel, the following vulnerability has been resolved: bpf: Send signals asynchronously if !preemptible BPF programs can execute in all kinds of…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.8th percentile
In the Linux kernel, the following vulnerability has been resolved: bpf: Send signals asynchronously if !preemptible BPF programs can execute in all kinds of contexts and when a program running in a non-preemptible context uses the bpf_send_signal() kfunc, it will cause issues because this kfunc can sleep. Change `irqs_disabled()` to `!preemptible()`.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 1bc7896e9ef44fd77858b3ef0b8a6840be3a4494 < ce51eab2070e295d298f42a2f1db269cd1b56d55ce51eab2070e295d298f42a2f1db269cd1b56d55
linuxlinux>= 1bc7896e9ef44fd77858b3ef0b8a6840be3a4494 < e306eaaa3d78b462db5f5b11e0171f9d2b6ca3f4e306eaaa3d78b462db5f5b11e0171f9d2b6ca3f4
linuxlinux>= 1bc7896e9ef44fd77858b3ef0b8a6840be3a4494 < be42a09fe898635b0093c0c8dac1bfabe225c240be42a09fe898635b0093c0c8dac1bfabe225c240
linuxlinux>= 1bc7896e9ef44fd77858b3ef0b8a6840be3a4494 < eeef8e65041a031bd8a747a392c14b76a123a12ceeef8e65041a031bd8a747a392c14b76a123a12c
linuxlinux>= 1bc7896e9ef44fd77858b3ef0b8a6840be3a4494 < 78b97783496b454435639937db3303e900a24d3f78b97783496b454435639937db3303e900a24d3f
linuxlinux>= 1bc7896e9ef44fd77858b3ef0b8a6840be3a4494 < 092fc76b7ab4163e008f9cde596a58dad2108260092fc76b7ab4163e008f9cde596a58dad2108260
linuxlinux>= 1bc7896e9ef44fd77858b3ef0b8a6840be3a4494 < 87c544108b612512b254c8f79aa5c0a8546e2cc487c544108b612512b254c8f79aa5c0a8546e2cc4
linuxlinux>= 5.4.33 < 5.4.2915.4.291
linuxlinux>= 5.5.18 < 5.65.6
linuxlinux>= fd29a0242f86b2d95ad666aa9f92a3d0f7bfdab6 < feba1308bc5e8e04cee751d39fae8a9b407a9034feba1308bc5e8e04cee751d39fae8a9b407a9034
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1296.1.129
linuxlinux_kernel>= 5.4.33 < 5.4.2915.4.291

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.