Linux Kernel Vulnerability in Rose Timers Affecting Google Compute Engine
CVE-2025-21718
Currently unrated
Summary
A vulnerability in the Linux kernel's rose timer functionality allows potential race conditions against user threads, which may lead to a use-after-free error. The issue occurs when rose timers only acquire a socket spinlock without checking the ownership of the socket. This oversight can be exploited, particularly under conditions of concurrent access, leading to unexpected behavior and possible instability in applications relying on rose timers.
Affected Version(s)
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 51c128ba038cf1b79d605cbee325919b45ab95a5
Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1992fb261c90e9827cf5dc3115d89bb0853252c9
References
Timeline
Vulnerability published
Vulnerability Reserved