CVE-2025-21769Resource Injection in Linux

CWE-99Resource Injection5 documents5 sources
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 67.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 27

Description

In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: Add .owner to vmclock_miscdev_fops Without the .owner field, the module can be unloaded while /dev/vmclock0 is open, leading to an oops.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDlinux/linux_kernel6.136.13.4+1
CVEListV5linux/linux20503272422693d793b84f88bf23fe4e955d3a333b5709225b43ee33e1026dd1fc0949a7f19b5289+2
debiandebian/linux

Patches

🔴Vulnerability Details

2
OSV
CVE-2025-21769: In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: Add2025-02-27
GHSA
GHSA-g2f3-xcg7-rxp6: In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: Add2025-02-27

📋Vendor Advisories

2
Red Hat
kernel: ptp: vmclock: Add .owner to vmclock_miscdev_fops2025-02-27
Debian
CVE-2025-21769: linux - In the Linux kernel, the following vulnerability has been resolved: ptp: vmcloc...2025
CVE-2025-21769 — Resource Injection in Linux | cvebase