cbcvebase.
CVE-2025-21965
published 2025-04-01

CVE-2025-21965: In the Linux kernel, the following vulnerability has been resolved: sched_ext: Validate prev_cpu in scx_bpf_select_cpu_dfl() If a BPF scheduler provides an…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved: sched_ext: Validate prev_cpu in scx_bpf_select_cpu_dfl() If a BPF scheduler provides an invalid CPU (outside the nr_cpu_ids range) as prev_cpu to scx_bpf_select_cpu_dfl() it can cause a kernel crash. To prevent this, validate prev_cpu in scx_bpf_select_cpu_dfl() and trigger an scx error if an invalid CPU is specified.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.20-1 (forky)linux 6.12.20-1 (forky)
linuxlinux
linuxlinux>= f0e1a0643a59bf1f922fa209cec86a170b784f3f < 752b56bb76e2471197d25d6948d85753043b10da752b56bb76e2471197d25d6948d85753043b10da
linuxlinux>= f0e1a0643a59bf1f922fa209cec86a170b784f3f < 515680e76c536dd4aa8e2b5d674b0d441baddf5b515680e76c536dd4aa8e2b5d674b0d441baddf5b
linuxlinux>= f0e1a0643a59bf1f922fa209cec86a170b784f3f < 9360dfe4cbd62ff1eb8217b815964931523b75b39360dfe4cbd62ff1eb8217b815964931523b75b3
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 6.12 < 6.12.206.12.20
linuxlinux_kernel>= 6.13 < 6.13.86.13.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.