Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2025-21777

5.5 · MEDIUM
Published Feb 27, 2025 linux EPSS 0.20% (10th pctl)

Overview

CVE-2025-21777 is a medium-severity vulnerability affecting linux linux_kernel. It was published on February 27, 2025 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ring-buffer: Validate the persistent meta data subbuf array

The meta data for a mapped ring buffer contains an array of indexes of all

the subbuffers. The first entry is the reader page, and the rest of the

entries lay out the order of the subbuffers in how the ring buffer link

list is to be created.

The validator currently makes sure that all the entries are within the

range of 0 and nr_subbufs. But it does not check if there are any

duplicates.

While working on the ring buffer, I corrupted this array, where I added

duplicates. The validator did not catch it and created the ring buffer

link list on top of it. Luckily, the corruption was only that the reader

page was also in the writer path and only presented corrupted data but did

not crash the kernel. But if there were duplicates in the writer side,

then it could corrupt the ring buffer link list and cause a crash.

Create a bitmask array with the size of the num

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 6.12, < 6.12.16 Affected

Frequently Asked Questions

What is CVE-2025-21777?

CVE-2025-21777 is a medium-severity vulnerability affecting linux linux_kernel. It was published on February 27, 2025 and has a CVSS 3.1 base score of 5.5 (MEDIUM).

How severe is CVE-2025-21777?

This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2025-21777?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2025-21777?

CyberStrike's AI-powered security agents can automatically detect CVE-2025-21777 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.