cbcvebase.
CVE-2025-21919
published 2025-04-01

CVE-2025-21919: In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix potential memory corruption in child_cfs_rq_on_list child_cfs_rq_on_list…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
9.9th percentile
In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix potential memory corruption in child_cfs_rq_on_list child_cfs_rq_on_list attempts to convert a 'prev' pointer to a cfs_rq. This 'prev' pointer can originate from struct rq's leaf_cfs_rq_list, making the conversion invalid and potentially leading to memory corruption. Depending on the relative positions of leaf_cfs_rq_list and the task group (tg) pointer within the struct, this can cause a memory fault or access garbage data. The issue arises in list_add_leaf_cfs_rq, where both cfs_rq->leaf_cfs_rq_list and rq->leaf_cfs_rq_list are added to the same leaf list. Also, rq->tmp_alone_branch can be set to rq->leaf_cfs_rq_list. This adds a check `if (prev == &rq->leaf_cfs_rq_list)` after the main conditional in child_cfs_rq_on_list. This ensures that the container_of operation will convert a correct cfs_rq struct. This check is sufficient because only cfs_rqs on the same CPU are added to the list, so verifying the 'prev' pointer against the current rq's list head is enough. Fixes a potential memory corruption issue that due to current struct layout might not be manifesting as a crash but could lead to unpredictable behavior when the layout changes.

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= fdaba61ef8a268d4136d0a113d153f7a89eb9984 < 5cb300dcdd27e6a351ac02541e0231261c7758525cb300dcdd27e6a351ac02541e0231261c775852
linuxlinux>= fdaba61ef8a268d4136d0a113d153f7a89eb9984 < 000c9ee43928f2ce68a156dd40bab7616256f4dd000c9ee43928f2ce68a156dd40bab7616256f4dd
linuxlinux>= fdaba61ef8a268d4136d0a113d153f7a89eb9984 < 9cc7f0018609f75a349e42e3aebc3b0e905ba7759cc7f0018609f75a349e42e3aebc3b0e905ba775
linuxlinux>= fdaba61ef8a268d4136d0a113d153f7a89eb9984 < b5741e4b9ef3567613b2351384f91d3f16e59986b5741e4b9ef3567613b2351384f91d3f16e59986
linuxlinux>= fdaba61ef8a268d4136d0a113d153f7a89eb9984 < e1dd09df30ba86716cb2ffab97dc35195c01eb8fe1dd09df30ba86716cb2ffab97dc35195c01eb8f
linuxlinux>= fdaba61ef8a268d4136d0a113d153f7a89eb9984 < 3b4035ddbfc8e4521f85569998a7569668cccf513b4035ddbfc8e4521f85569998a7569668cccf51
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 5.13 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1316.1.131
linuxlinux_kernel>= 6.13 < 6.13.76.13.7
linuxlinux_kernel>= 6.2 < 6.6.836.6.83
linuxlinux_kernel>= 6.7 < 6.12.196.12.19
msrcazl3_kernel_6.6.82.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.