cbcvebase.
CVE-2025-21950
published 2025-04-01

CVE-2025-21950: In the Linux kernel, the following vulnerability has been resolved: drivers: virt: acrn: hsm: Use kzalloc to avoid info leak in pmcmd_ioctl In the…

PriorityP428high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.19%
9.2th percentile
In the Linux kernel, the following vulnerability has been resolved: drivers: virt: acrn: hsm: Use kzalloc to avoid info leak in pmcmd_ioctl In the "pmcmd_ioctl" function, three memory objects allocated by kmalloc are initialized by "hcall_get_cpu_state", which are then copied to user space. The initializer is indeed implemented in "acrn_hypercall2" (arch/x86/include/asm/acrn.h). There is a risk of information leakage due to uninitialized bytes.

Affected

21 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= 3d679d5aec648f50e645702929890b9611998a0b < 4e15cf870d2c748e45d45ffc4d5b1dc1b7d501204e15cf870d2c748e45d45ffc4d5b1dc1b7d50120
linuxlinux>= 3d679d5aec648f50e645702929890b9611998a0b < 524f29d78c9bdeb49f31f5b0376a07d2fc5cf563524f29d78c9bdeb49f31f5b0376a07d2fc5cf563
linuxlinux>= 3d679d5aec648f50e645702929890b9611998a0b < d7e5031fe3f161c8eb5e84db1540bc4373ed861bd7e5031fe3f161c8eb5e84db1540bc4373ed861b
linuxlinux>= 3d679d5aec648f50e645702929890b9611998a0b < 1b8f7a2caa7f9cdfd135e3f78eb9d7e36fb950831b8f7a2caa7f9cdfd135e3f78eb9d7e36fb95083
linuxlinux>= 3d679d5aec648f50e645702929890b9611998a0b < a4c21b878f0e237f45209a324c903ea7fb05247da4c21b878f0e237f45209a324c903ea7fb05247d
linuxlinux>= 3d679d5aec648f50e645702929890b9611998a0b < 819cec1dc47cdeac8f5dd6ba81c1dbee2a68c3bb819cec1dc47cdeac8f5dd6ba81c1dbee2a68c3bb
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 5.12 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1316.1.131
linuxlinux_kernel>= 6.13 < 6.13.76.13.7
linuxlinux_kernel>= 6.2 < 6.6.836.6.83
linuxlinux_kernel>= 6.7 < 6.12.196.12.19

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.