Linux Kernel Vulnerability in l3mdev Functionality by The Linux Foundation
CVE-2025-21791

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
27 February 2025

What is CVE-2025-21791?

A security flaw was identified within the Linux kernel related to the l3mdev function that could be exploited if RCU protection is not properly implemented. The vulnerability arises when the l3mdev_l3_out() function is executed without the required RCU lock, leading to a potential Use After Free (UAF) scenario. This issue necessitates the implementation of rcu_read_lock() and rcu_read_unlock() calls in the code to safeguard against unauthorized memory access and ensure robust data integrity in networking operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux a8e3e1a9f02094145580ea7920c6a1d9aabd5539 < 6ccaa5797f5362a2aad6baa6ddaf4715ac2dd51e

Linux a8e3e1a9f02094145580ea7920c6a1d9aabd5539 < 20a3489b396764cc9376e32a9172bee26a89dc3b

Linux a8e3e1a9f02094145580ea7920c6a1d9aabd5539 < 5bb4228c32261d06e4fbece37ec3828bcc005b6b

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.