CVE-2025-21672
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2025-21672 is a vulnerability affecting the Linux kernel that was recently addressed. Afs: Fix merge preference rule failure condition was the issue identified, where a lock held by a function named syz-executor133/5823 was not released properly when argc was less than 0 and the function returned directly. This led to a warning of a lock held when returning to user space. The vulnerability has been rectified by storing the error in ret and jumping to done to clean up instead of returning directly. The patch was modified by DH to honor the error code from afs_split_string(). This issue was first discovered during a syzkaller run, and it was observed that the lock was still held by syz-executor133/5823 when leaving the kernel.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.