CVE-2025-21671

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
31/01/2025
Last modified:
10/02/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> zram: fix potential UAF of zram table<br /> <br /> If zram_meta_alloc failed early, it frees allocated zram-&gt;table without<br /> setting it NULL. Which will potentially cause zram_meta_free to access<br /> the table if user reset an failed and uninitialized device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.1.122 (including) 6.1.127 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.6.68 (including) 6.6.74 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.12.7 (including) 6.12.11 (excluding)