Use-after-free Vulnerability in Linux Kernel Affecting Btrfs File System
CVE-2025-21753

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
27 February 2025

What is CVE-2025-21753?

A use-after-free vulnerability exists within the Btrfs file system of the Linux Kernel, where the current transaction's aborted state can be read after the related lock is released. This flaw allows an attacker to exploit the premature freeing of memory, potentially leading to arbitrary code execution or system crashes. It has been addressed by modifying the sequence in which the transaction's aborted state is accessed, ensuring that the necessary locks are held to prevent concurrency issues. Regular updates should be applied to systems running vulnerable versions to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 871383be592ba7e819d27556591e315a0df38cee

Linux 871383be592ba7e819d27556591e315a0df38cee

Linux 871383be592ba7e819d27556591e315a0df38cee < 7e954b6bb95d67ae4d1a20e9cfd83c182cf929bc

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.