Use-After-Free Vulnerability in Linux Kernel Padata Module
CVE-2025-21727
Summary
A vulnerability exists within the Linux kernel related to the padata module where a use-after-free condition can occur. When functions in the padata_reorder loop are executed, if the algorithm is deleted prior to invoking padata_find_next, this can result in accessing a freed memory space. This bug is easily reproducible during specific testing scenarios, emphasizing the need for timely patching to prevent exploitation. The issue arises from improper management of reference counts during parallel and serial processing of cryptographic data, which may lead to potential system instability and security risks.
Affected Version(s)
Linux b128a30409356df65f1a51cff3eb986cac8cfedc < 0ae2f332cfd2d74cf3ce344ec9938cf3e29c3ccd
Linux b128a30409356df65f1a51cff3eb986cac8cfedc
Linux b128a30409356df65f1a51cff3eb986cac8cfedc < 573ac9c70bf7885dc85d82fa44550581bfc3b738
References
Timeline
Vulnerability published
Vulnerability Reserved