CVE-2025-21729
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2025-21729 is a vulnerability affecting the Linux kernel's wifi driver rtw89. The issue lies in a race condition between the cancellation of an ongoing hardware scan and the completion of the scan. As a result, the rtwdev->scanning flag is not properly protected by a mutex, leading to null-pointer dereferencing and use-after-free when the scan completion unset the flag and called a function that frees the scan request. This vulnerability can potentially lead to system crashes and other security implications. The affected CPU is a Lenovo system with a kernel version of 2.76, and the issue was discovered during a kernel address sanitizer (KASAN) scan.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Linux Kernel
Affected Vendors
- LINUX