CVE-2025-21862

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 12, 2025
Updated: Mar 13, 2025
CWE ID 908

Summary

CVE-2025-21862 involves a vulnerability in the Linux kernel's drop_monitor component. Syzkaller discovered a bug where the spinlock used by net_dm_cmd_trace was not yet initialized when net_dm_monitor_start() was called during the loading of the drop_monitor kernel module. To mitigate this issue, the initialization of resources should be prioritized before the registration of the generic netlink family. This vulnerability was found by InfoTeCS on behalf of the Linux Verification Center.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share