CVE-2025-21729Use After Free in Linux

CWE-416Use After Free24 documents7 sources
Severity
7.8HIGHNVD
OSV7.1
EPSS
0.0%
top 93.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 27
Latest updateJan 9

Description

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix race between cancel_hw_scan and hw_scan completion The rtwdev->scanning flag isn't protected by mutex originally, so cancel_hw_scan can pass the condition, but suddenly hw_scan completion unset the flag and calls ieee80211_scan_completed() that will free local->hw_scan_req. Then, cancel_hw_scan raises null-ptr-deref and use-after-free. Fix it by moving the check condition to where protected by mutex. KASAN: n

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

NVDlinux/linux_kernel5.186.12.13+1
Debianlinux/linux_kernel< 6.12.13-1+1
Ubuntulinux/linux_kernel< 6.8.0-88.89
CVEListV5linux/linux895907779752606f6a4795abfc008509f8e383142403cb3c235d5e339b580cc3a825493769fadca8+3

Patches

🔴Vulnerability Details

12
OSV
linux-azure-nvidia vulnerabilities2026-01-09
OSV
linux-azure-fips vulnerabilities2025-12-17
OSV
linux-raspi, linux-raspi-realtime, linux-xilinx vulnerabilities2025-12-16
OSV
linux-azure, linux-azure-6.8 vulnerabilities2025-12-15
OSV
linux-hwe-6.8, linux-oracle-6.8 vulnerabilities2025-12-11

📋Vendor Advisories

11
Ubuntu
Linux kernel (Azure, N-Series) vulnerabilities2026-01-09
Ubuntu
Linux kernel (Azure FIPS) vulnerabilities2025-12-17
Ubuntu
Linux kernel vulnerabilities2025-12-16
Ubuntu
Linux kernel (Azure) vulnerabilities2025-12-15
Ubuntu
Linux kernel vulnerabilities2025-12-11