CVE-2025-21692

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 10, 2025
Updated: Feb 21, 2025
CWE ID 129

Summary

CVE-2025-21692 is a newly disclosed vulnerability in the Linux kernel that allows for local privilege escalation. Haowei Yan discovered that the function ets_class_change can index an Out-Of-Bound class in ets_class_from_arg(), leading to an overflow. This issue was first observed during a use-after-free condition, resulting in a UBSAN warning and potential index out-of-bounds error. The vulnerability was reported to affect Linux version 6.12.6-dirty and could potentially impact other versions as well. The call stack indicates that the issue was triggered during a netlink_rcv_skb function call, highlighting the importance of timely patching to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share