cbcvebase.
CVE-2025-21781
published 2025-02-27

CVE-2025-21781: In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix panic during interface removal Reference counting is used to ensure that…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
11.8th percentile
In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix panic during interface removal Reference counting is used to ensure that batadv_hardif_neigh_node and batadv_hard_iface are not freed before/during batadv_v_elp_throughput_metric_update work is finished. But there isn't a guarantee that the hard if will remain associated with a soft interface up until the work is finished. This fixes a crash triggered by reboot that looks like this: Call trace: batadv_v_mesh_free+0xd0/0x4dc [batman_adv] batadv_v_elp_throughput_metric_update+0x1c/0xa4 process_one_work+0x178/0x398 worker_thread+0x2e8/0x4d0 kthread+0xd8/0xdc ret_from_fork+0x10/0x20 (the batadv_v_mesh_free call is misleading, and does not actually happen) I was able to make the issue happen more reliably by changing hardif_neigh->bat_v.metric_work work to be delayed work. This allowed me to track down and confirm the fix. [[email protected]: prevent entering batadv_v_elp_get_throughput without soft_iface]

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
googlechrome_chrome
linuxlinux
linuxlinux>= c833484e5f3872a38fe232c663586069d5ad9645 < 167422a07096a6006599067c8b55884064fa0b72167422a07096a6006599067c8b55884064fa0b72
linuxlinux>= c833484e5f3872a38fe232c663586069d5ad9645 < ce3f1545bf8fa28bd05ec113679e8e6cd23af577ce3f1545bf8fa28bd05ec113679e8e6cd23af577
linuxlinux>= c833484e5f3872a38fe232c663586069d5ad9645 < f0a16c6c79768180333f3e41ce63f32730e3c3aff0a16c6c79768180333f3e41ce63f32730e3c3af
linuxlinux>= c833484e5f3872a38fe232c663586069d5ad9645 < 7eb5dd201695645af071592a50026eb780081a727eb5dd201695645af071592a50026eb780081a72
linuxlinux>= c833484e5f3872a38fe232c663586069d5ad9645 < 072b2787321903287a126c148e8db87dd7ef96fe072b2787321903287a126c148e8db87dd7ef96fe
linuxlinux>= c833484e5f3872a38fe232c663586069d5ad9645 < 2c3fb7df4cc6d043f70d4a8a10f8b915bbfb75e72c3fb7df4cc6d043f70d4a8a10f8b915bbfb75e7
linuxlinux>= c833484e5f3872a38fe232c663586069d5ad9645 < 522b1596ea19e327853804da2de60aeb9c5d6f42522b1596ea19e327853804da2de60aeb9c5d6f42
linuxlinux>= c833484e5f3872a38fe232c663586069d5ad9645 < ccb7276a6d26d6f8416e315b43b45e15ee7f29e2ccb7276a6d26d6f8416e315b43b45e15ee7f29e2
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-78.786.8.0-78.78
linuxlinux_kernel>= 4.6 < 5.4.2915.4.291
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1296.1.129
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.46.13.4

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.