cbcvebase.
CVE-2025-21739
published 2025-02-27

CVE-2025-21739: In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix use-after free in init error and remove paths…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
12.6th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Fix use-after free in init error and remove paths devm_blk_crypto_profile_init() registers a cleanup handler to run when the associated (platform-) device is being released. For UFS, the crypto private data and pointers are stored as part of the ufs_hba's data structure 'struct ufs_hba::crypto_profile'. This structure is allocated as part of the underlying ufshcd and therefore Scsi_host allocation. During driver release or during error handling in ufshcd_pltfrm_init(), this structure is released as part of ufshcd_dealloc_host() before the (platform-) device associated with the crypto call above is released. Once this device is released, the crypto cleanup code will run, using the just-released 'struct ufs_hba::crypto_profile'. This causes a use-after-free situation: Call trace: kfree+0x60/0x2d8 (P) kvfree+0x44/0x60 blk_crypto_profile_destroy_callback+0x28/0x70 devm_action_release+0x1c/0x30 release_nodes+0x6c/0x108 devres_release_all+0x98/0x100 device_unbind_cleanup+0x20/0x70 really_probe+0x218/0x2d0 In other words, the initialisation code flow is: platform-device probe ufshcd_pltfrm_init() ufshcd_alloc_host() scsi_host_alloc() allocation of struct ufs_hba creation of scsi-host devices devm_blk_crypto_profile_init() devm registration of cleanup handler using platform-device and during error handling of ufshcd_pltfrm_init() or during driver removal: ufshcd_dealloc_host() scsi_host_put() put_device(scsi-host) release of struct ufs_hba put_device(platform-device) crypto cleanup handler To fix this use-after free, change ufshcd_alloc_host() to register a devres action to automatically cleanup the underlying SCSI device on ufshcd destruction, without requiring explicit calls to ufshcd_dealloc_host(). This way: * the crypto profile and all other ufs_hba-owned resources are destroyed before SCSI (as they've been registered after) * a memleak is plugged in tc-dwc-g210-pci.c remove(

Affected

49 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.15-1 (forky)linux 6.12.15-1 (forky)
linuxlinux
linuxlinux>= d76d9d7d1009968dd3a0fc30e5f5ee9fbffc1350 < 0a6895c03b1f439236e2d22b1a69ebfc1eb9d5ea0a6895c03b1f439236e2d22b1a69ebfc1eb9d5ea
linuxlinux>= d76d9d7d1009968dd3a0fc30e5f5ee9fbffc1350 < d06eb2620d3bf16056b8b7ea3744dbb5e30512f4d06eb2620d3bf16056b8b7ea3744dbb5e30512f4
linuxlinux>= d76d9d7d1009968dd3a0fc30e5f5ee9fbffc1350 < 0dc539b888fb5f56b6eeddd95433eab557d4b0c10dc539b888fb5f56b6eeddd95433eab557d4b0c1
linuxlinux>= d76d9d7d1009968dd3a0fc30e5f5ee9fbffc1350 < 0c77c0d754fe83cb154715fcfec6c3faef94f2070c77c0d754fe83cb154715fcfec6c3faef94f207
linuxlinux>= d76d9d7d1009968dd3a0fc30e5f5ee9fbffc1350 < 9c185beae09a3eb85f54777edafa227f7e03075d9c185beae09a3eb85f54777edafa227f7e03075d
linuxlinux>= d76d9d7d1009968dd3a0fc30e5f5ee9fbffc1350 < f8fb2403ddebb5eea0033d90d9daae4c88749adaf8fb2403ddebb5eea0033d90d9daae4c88749ada
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67
linuxlinux_kernel>= 5.12 < 6.12.146.12.14
linuxlinux_kernel>= 6.13 < 6.13.36.13.3
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.112.1-2_on_azure_linux_3.0
msrcazl3_kernel_6.6.117.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.119.3-3_on_azure_linux_3.0
msrcazl3_kernel_6.6.121.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.126.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.130.1-3_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.