CVE-2025-21861Use After Free in Linux

CWE-416Use After Free40 documents7 sources
Severity
5.5MEDIUMNVD
OSV7.8
EPSS
0.0%
top 97.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 12
Latest updateApr 13

Description

In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: don't add folio to be freed to LRU in migrate_device_finalize() If migration succeeded, we called folio_migrate_flags()->mem_cgroup_migrate() to migrate the memcg from the old to the new folio. This will set memcg_data of the old folio to 0. Similarly, if migration failed, memcg_data of the dst folio is left unset. If we call folio_putback_lru() on such folios (memcg_data == 0), we will add the folio to be

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages8 packages

NVDlinux/linux_kernel4.146.12.17+2
Debianlinux/linux_kernel< 5.10.247-1+3
Ubuntulinux/linux_kernel< 5.15.0-170.180+1
CVEListV5linux/linux8763cb45ab967a92a5ee49e9c544c0f0ea90e2d661fa824e304ed162fe965f64999068e6fcff2059+8

Patches

🔴Vulnerability Details

19
OSV
linux-raspi vulnerabilities2026-04-01
OSV
linux-intel-iotg-5.15, linux-xilinx-zynqmp vulnerabilities2026-02-19
OSV
linux-intel-iotg vulnerabilities2026-02-19
OSV
linux-nvidia vulnerabilities2026-02-17
OSV
linux-nvidia-tegra-igx vulnerabilities2026-02-17

📋Vendor Advisories

20
Ubuntu
Linux kernel (Azure) vulnerabilities2026-04-13
Ubuntu
Linux kernel (Azure FIPS) vulnerabilities2026-04-09
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2026-04-01
Ubuntu
Linux kernel (Intel IoTG) vulnerabilities2026-02-19
Ubuntu
Linux kernel (NVIDIA) vulnerabilities2026-02-17