CVE-2025-21671

HIGH

Linux Kernel 6.1.122-6.1.126, 6.6.68-6.6.73, 6.12.7-6.12.10 - Use-After-Free in zram Table Handling

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: zram: fix potential UAF of zram table If zram_meta_alloc failed early, it frees allocated zram->table without setting it NULL. Which will potentially cause zram_meta_free to access the table if user reset an failed and uninitialized device.

Scores

CVSS v3 7.8
EPSS 0.0020
EPSS Percentile 10.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (11)
linux/Kernel 6.1.122 - 6.1.127linux
linux/Kernel 6.12.7 - 6.12.11linux
linux/Kernel 6.6.68 - 6.6.74linux
Linux/Linux 0b5b0b65561b34e6e360de317e4bcd031bfabf42 - 571d3f6045cd3a6d9f6aec33b678f3ffe97582ef
Linux/Linux 6.1.122 - 6.1.127
Linux/Linux 6.12.7 - 6.12.11
Linux/Linux 6.6.68 - 6.6.74
Linux/Linux 6fb92e9a52e3feae309a213950f21dfcd1eb0b40 - 902ef8f16d5ca77edc77c30656be54186c1e99b7
Linux/Linux 74363ec674cb172d8856de25776c8f3103f05e2f - 212fe1c0df4a150fb6298db2cfff267ceaba5402
Linux/Linux ac3b5366b9b7c9d97b606532ceab43d2329a22f3 - fe3de867f94819ba0f28e035c0b0182150147d95
... and 1 more
Published Jan 31, 2025
Tracked Since Feb 18, 2026