CVE-2025-21846
acct: perform last write from workqueue
Record summary
CVE-2025-21846 has a selected CVSS score of 5.5 (medium).
Description
In the Linux kernel, the following vulnerability has been resolved: acct: perform last write from workqueue In [1] it was reported that the acct(2) system call can be used to trigger NULL deref in cases where it is set to write to a file that triggers an internal lookup. This can e.g., happen when pointing acc(2) to /sys/power/resume. At the point the where the write to this file happens the calling task has already exited and called exit_fs(). A lookup will thus trigger a NULL-deref when accessing current->fs. Reorganize the code so that the the final write happens from the workqueue but with the caller's credentials. This preserves the (strange) permission model and has almost no regression risk. This api should stop to exist though.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 1, 2025 · Source: CVE List
Affected products and versions
6| Product | Source | Version range | Status |
|---|---|---|---|
LinuxBrowse Linux / LinuxDefault status: unaffected, affected | CVE List | 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to < 8acbf4a88c6a98c8ed00afd1a7d1abcca9b4735e | affected |
| 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to < b03782ae707cc45e65242c7cddd8e28f1c22cde5 | affected | ||
| 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to < 5d5b936cfa4b0d5670ca7420ef165a074bc008eb | affected | ||
| 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to < 5ee8da9bea70dda492d61f075658939af33d8410 | affected | ||
| 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to < 5c928e14a2ccd99462f2351ead627b58075bb736 | affected | ||
| 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to < 5a59ced8ffc71973d42c82484a719c8f6ac8f7f7 | affected | ||
| 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to < a8136afca090412a36429cb6c2543c714d9c0f84 | affected | ||
| 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 to < 56d5f3eba3f5de0efdd556de4ef381e109b973a9 | affected | ||
| 2.6.12 | affected | ||
| Before 2.6.12 | unaffected | ||
| 5.4.291 to ≤ 5.4.* | unaffected | ||
| 5.10.235 to ≤ 5.10.* | unaffected | ||
| Showing 12 of 18 version ranges | |||
SIMATIC S7-1500 CPU 1518-4 PN/DP MFPBrowse Siemens / SIMATIC S7-1500 CPU 1518-4 PN/DP MFPDefault status: unknown | CVE List | V3.1.6 to < * | affected |
SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPBrowse Siemens / SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPDefault status: unknown | CVE List | V3.1.6 to < * | affected |
SIMATIC S7-1500 TM MFP - GNU/Linux subsystemBrowse Siemens / SIMATIC S7-1500 TM MFP - GNU/Linux subsystemDefault status: unknown | CVE List | Before * | affected |
SIPLUS S7-1500 CPU 1518-4 PN/DP MFPBrowse Siemens / SIPLUS S7-1500 CPU 1518-4 PN/DP MFPDefault status: unknown | CVE List | V3.1.6 to < * | affected |
KernelBrowse Linux / Kernel | OSV | 2.6.12 to < 5.4.291 · Fixed in 5.4.291 | affected |
| 5.5.0 to < 5.10.235 · Fixed in 5.10.235 | affected | ||
| 5.11.0 to < 5.15.179 · Fixed in 5.15.179 | affected | ||
| 5.16.0 to < 6.1.130 · Fixed in 6.1.130 | affected | ||
| 6.2.0 to < 6.6.80 · Fixed in 6.6.80 | affected | ||
| 6.7.0 to < 6.12.17 · Fixed in 6.12.17 | affected | ||
| 6.13.0 to < 6.13.5 · Fixed in 6.13.5 | affected | ||