Wind River Support Network

HomeDefectsLIN1021-14349
Acknowledged

LIN1021-14349 : Security Advisory - linux - CVE-2025-21726

Created: Feb 27, 2025    Updated: Jun 17, 2025
Found In Version: 10.21.20.1
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:padata: avoid UAF for reorder_workAlthough the previous patch can avoid ps and ps UAF for _do_serial, itcan not avoid potential UAF issue for reorder_work. This issue canhappen just as below:crypto_request                      crypto_request          crypto_del_algpadata_do_serial  ...  padata_reorder    // processes all remaining    // requests then breaks    while (1) {      if (!padata)        break;      ...    }                             padata_do_serial                        // new request added                             list_add    // sees the new request    queue_work(reorder_work)                                padata_reorder                                    queue_work_on(squeue->work)...                             <kworker context>                               padata_serial_worker          // completes new request,                                // no more outstanding                          // requests                                                    crypto_del_alg                                          // free pd<kworker context>invoke_padata_reorder  // UAF of pdTo avoid UAF for 'reorder_work', get 'pd' ref before put 'reorder_work'into the 'serial_wq' and put 'pd' ref until the 'serial_wq' finish.

CREATE(Triage):(User=admin) CVE-2025-21726 (https://nvd.nist.gov/vuln/detail/CVE-2025-21726)
Live chat
Online