CVE-2025-21988

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/04/2025
Last modified:
04/11/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> fs/netfs/read_collect: add to next-&gt;prev_donated<br /> <br /> If multiple subrequests donate data to the same "next" request<br /> (depending on the subrequest completion order), each of them would<br /> overwrite the `prev_donated` field, causing data corruption and a<br /> BUG() crash ("Can&amp;#39;t donate prior to front").

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.12 (including) 6.12.20 (excluding)
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 6.13 (including) 6.13.8 (excluding)