cbcvebase.
CVE-2025-21731
published 2025-02-27

CVE-2025-21731: In the Linux kernel, the following vulnerability has been resolved: nbd: don't allow reconnect after disconnect Following process can cause nbd_config UAF: 1)…

PriorityP336high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
12.5th percentile
In the Linux kernel, the following vulnerability has been resolved: nbd: don't allow reconnect after disconnect Following process can cause nbd_config UAF: 1) grab nbd_config temporarily; 2) nbd_genl_disconnect() flush all recv_work() and release the initial reference: nbd_genl_disconnect nbd_disconnect_and_put nbd_disconnect flush_workqueue(nbd->recv_workq) if (test_and_clear_bit(NBD_RT_HAS_CONFIG_REF, ...)) nbd_config_put -> due to step 1), reference is still not zero 3) nbd_genl_reconfigure() queue recv_work() again; nbd_genl_reconfigure config = nbd_get_config_unlocked(nbd) if (!config) -> succeed if (!test_bit(NBD_RT_BOUND, ...)) -> succeed nbd_reconnect_socket queue_work(nbd->recv_workq, &args->work) 4) step 1) release the reference; 5) Finially, recv_work() will trigger UAF: recv_work nbd_config_put(nbd) -> nbd_config is freed atomic_dec(&config->recv_threads) -> UAF Fix the problem by clearing NBD_RT_BOUND in nbd_genl_disconnect(), so that nbd_genl_reconfigure() will fail.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux>= b7aa3d39385dc2d95899f9e379623fef446a2acd < e70a578487a47d7cf058904141e586684d1c3381e70a578487a47d7cf058904141e586684d1c3381
linuxlinux>= b7aa3d39385dc2d95899f9e379623fef446a2acd < 6bef6222a3f6c7adb6396f77f25a3579d821b09a6bef6222a3f6c7adb6396f77f25a3579d821b09a
linuxlinux>= b7aa3d39385dc2d95899f9e379623fef446a2acd < e3be8862d73cac833e0fb7602636c19c6cb94b11e3be8862d73cac833e0fb7602636c19c6cb94b11
linuxlinux>= b7aa3d39385dc2d95899f9e379623fef446a2acd < e7343fa33751cb07c1c56b666bf37cfca357130ee7343fa33751cb07c1c56b666bf37cfca357130e
linuxlinux>= b7aa3d39385dc2d95899f9e379623fef446a2acd < d208d2c52b652913b5eefc8ca434b0d6b757f68fd208d2c52b652913b5eefc8ca434b0d6b757f68f
linuxlinux>= b7aa3d39385dc2d95899f9e379623fef446a2acd < a8ee6ecde2b7bfb58c8a3afe8a9d2b848f580739a8ee6ecde2b7bfb58c8a3afe8a9d2b848f580739
linuxlinux>= b7aa3d39385dc2d95899f9e379623fef446a2acd < 9793bd5ae4bdbdb2dde401a3cab94a6bfd05e3029793bd5ae4bdbdb2dde401a3cab94a6bfd05e302
linuxlinux>= b7aa3d39385dc2d95899f9e379623fef446a2acd < 844b8cdc681612ff24df62cdefddeab5772fadf1844b8cdc681612ff24df62cdefddeab5772fadf1
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67
linuxlinux_kernel>= 4.12 < 5.4.2915.4.291
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1296.1.129
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.26.13.2
linuxlinux_kernel>= 6.2 < 6.6.766.6.76
linuxlinux_kernel>= 6.7 < 6.12.136.12.13

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.