BPF Map Vulnerability in Linux Kernel
CVE-2025-21853

5.5MEDIUM

Key Information:

Vendor
Linux
Status
Vendor
CVE Published:
12 March 2025

Summary

A design flaw in the Linux kernel related to BPF maps has been identified. The issue arises from holding the freeze_mutex during the entire mmap operation, which is unnecessary and can lead to potential deadlocks. By only holding the mutex during writeability checks and then proceeding with the mmap logic allows for better performance and reduces the risk of deadlocks. Proper handling of the 'write active' count ensures that any errors encountered during mmap can be managed effectively.

Affected Version(s)

Linux fc9702273e2edb90400a34b3be76f7b08fa3344b < 29cfda62ab4d92ab94123813db49ab76c1e61b29

Linux fc9702273e2edb90400a34b3be76f7b08fa3344b

Linux fc9702273e2edb90400a34b3be76f7b08fa3344b < 271e49f8a58edba65bc2b1250a0abaa98c4bfdbe

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.