Use-After-Free Vulnerability in Linux Kernel Padata Module
CVE-2025-21727

Currently unrated

Key Information:

Vendor
Linux
Status
Vendor
CVE Published:
27 February 2025

Summary

A vulnerability exists within the Linux kernel related to the padata module where a use-after-free condition can occur. When functions in the padata_reorder loop are executed, if the algorithm is deleted prior to invoking padata_find_next, this can result in accessing a freed memory space. This bug is easily reproducible during specific testing scenarios, emphasizing the need for timely patching to prevent exploitation. The issue arises from improper management of reference counts during parallel and serial processing of cryptographic data, which may lead to potential system instability and security risks.

Affected Version(s)

Linux b128a30409356df65f1a51cff3eb986cac8cfedc < 0ae2f332cfd2d74cf3ce344ec9938cf3e29c3ccd

Linux b128a30409356df65f1a51cff3eb986cac8cfedc

Linux b128a30409356df65f1a51cff3eb986cac8cfedc < 573ac9c70bf7885dc85d82fa44550581bfc3b738

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.