U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-21633

Change History

CVE Modified by kernel.org 5/20/2025 10:15:27 AM

Action Type Old Value New Value
Changed Description
In the Linux kernel, the following vulnerability has been resolved:

io_uring/sqpoll: zero sqd->thread on tctx errors

Syzkeller reports:

BUG: KASAN: slab-use-after-free in thread_group_cputime+0x409/0x700 kernel/sched/cputime.c:341
Read of size 8 at addr ffff88803578c510 by task syz.2.3223/27552
 Call Trace:
  <TASK>
  ...
  kasan_report+0x143/0x180 mm/kasan/report.c:602
  thread_group_cputime+0x409/0x700 kernel/sched/cputime.c:341
  thread_group_cputime_adjusted+0xa6/0x340 kernel/sched/cputime.c:639
  getrusage+0x1000/0x1340 kernel/sys.c:1863
  io_uring_show_fdinfo+0xdfe/0x1770 io_uring/fdinfo.c:197
  seq_show+0x608/0x770 fs/proc/fd.c:68
  ...

That's due to sqd->task not being cleared properly in cases where
SQPOLL task tctx setup fails, which can essentially only happen with
fault injection to insert allocation errors.
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Removed CVSS V3.1
CISA-ADP: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

								
						
Removed CWE
CISA-ADP: CWE-416

								
						
Removed CPE Configuration
OR
          *cpe:2.3:o:linux:linux_kernel:6.13:rc2:*:*:*:*:*:*
          *cpe:2.3:o:linux:linux_kernel:6.13:rc1:*:*:*:*:*:*
          *cpe:2.3:o:linux:linux_kernel:6.13:rc3:*:*:*:*:*:*
          *cpe:2.3:o:linux:linux_kernel:6.13:rc4:*:*:*:*:*:*
          *cpe:2.3:o:linux:linux_kernel:6.13:rc5:*:*:*:*:*:*
          *cpe:2.3:o:linux:linux_kernel:6.13:rc6:*:*:*:*:*:*
          *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.9 up to (excluding) 6.12.10

								
						
Removed Reference
kernel.org: https://git.kernel.org/stable/c/4b7cfa8b6c28a9fa22b86894166a1a34f6d630ba

								
						
Removed Reference
kernel.org: https://git.kernel.org/stable/c/aa7496d668c30ca7421b3bfdcd948ee861a13d17

								
						
Removed Reference Type
kernel.org: https://git.kernel.org/stable/c/4b7cfa8b6c28a9fa22b86894166a1a34f6d630ba Types: Patch

								
						
Removed Reference Type
kernel.org: https://git.kernel.org/stable/c/aa7496d668c30ca7421b3bfdcd948ee861a13d17 Types: Patch

								
						

CVE Rejected by kernel.org 5/20/2025 10:15:27 AM

Action Type Old Value New Value