Linux Kernel Vulnerability in Rose Timers Affecting Google Compute Engine
CVE-2025-21718

Currently unrated

Key Information:

Vendor
Linux
Status
Vendor
CVE Published:
27 February 2025

Summary

A vulnerability in the Linux kernel's rose timer functionality allows potential race conditions against user threads, which may lead to a use-after-free error. The issue occurs when rose timers only acquire a socket spinlock without checking the ownership of the socket. This oversight can be exploited, particularly under conditions of concurrent access, leading to unexpected behavior and possible instability in applications relying on rose timers.

Affected Version(s)

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 51c128ba038cf1b79d605cbee325919b45ab95a5

Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1992fb261c90e9827cf5dc3115d89bb0853252c9

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.