THREAT OPS › Threat News › [NVD] CVE-2025-21836 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved:
io_uring/kbuf: reallocate buf lists on upgrade
IORING_REGISTER_PBUF_RING can reuse an old struct io_buffer_list if it
was created for legacy selected buffer and has been emptied. It violates
the requirement tha
[NVD] CVE-2025-21836 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: reallocate buf lists on upgrade IORING_REGISTER_PBUF_RING can reuse an old struct io_buffer_list if it was created for legacy selected buffer and has been emptied. It violates the requirement tha
CVE-2025-21836 CVSS: 7.8 HIGH Published: 2025-03-07T09:15:16.600
In the Linux kernel, the following vulnerability has been resolved:
io_uring/kbuf: reallocate buf lists on upgrade
IORING_REGISTER_PBUF_RING can reuse an old struct io_buffer_list if it was created for legacy selected buffer and has been emptied. It violates the requirement that most of the field should stay stable after publish.
Indicators of compromise
- CVE-2025-21836cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-21836