cbcvebase.
CVE-2025-21836
published 2025-03-07

CVE-2025-21836: In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: reallocate buf lists on upgrade IORING_REGISTER_PBUF_RING can reuse an old…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.0th percentile
In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: reallocate buf lists on upgrade IORING_REGISTER_PBUF_RING can reuse an old struct io_buffer_list if it was created for legacy selected buffer and has been emptied. It violates the requirement that most of the field should stay stable after publish. Always reallocate it instead.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.16-1 (forky)linux 6.12.16-1 (forky)
googlechrome_chrome
linuxlinux
linuxlinux>= 2fcabce2d7d34f69a888146dab15b36a917f09d4 < 146a185f6c05ee263db715f860620606303c4633146a185f6c05ee263db715f860620606303c4633
linuxlinux>= 2fcabce2d7d34f69a888146dab15b36a917f09d4 < 7d0dc28dae836caf7645fef62a10befc624dd17b7d0dc28dae836caf7645fef62a10befc624dd17b
linuxlinux>= 2fcabce2d7d34f69a888146dab15b36a917f09d4 < 2a5febbef40ce968e295a7aeaa5d5cbd9e3e5ad42a5febbef40ce968e295a7aeaa5d5cbd9e3e5ad4
linuxlinux>= 2fcabce2d7d34f69a888146dab15b36a917f09d4 < 8802766324e1f5d414a81ac43365c20142e856038802766324e1f5d414a81ac43365c20142e85603
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 6.8.0-78.786.8.0-78.78
linuxlinux_kernel>= 5.19 < 6.6.796.6.79
linuxlinux_kernel>= 6.13 < 6.13.46.13.4
linuxlinux_kernel>= 6.7 < 6.12.166.12.16

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.