CVE-2025-21836
In the Linux kernel, the following vulnerability has been resolved: io_uring/kbuf: reallocate buf lists on upgrade IORING_REGISTER_PBUF_RING can reuse an old struct io_buffer_list if it was created for legacy selected buffer and has been emptied. It violates the requirement that most of the field should stay stable after publish. Always reallocate it instead.
- Affected products
- Astra Linux, Debian, Linuxmint, Linux Kernel, Suse, Ubuntu
- Linux Linux Kernel
- < 6.6.79, 6.12.16, 6.13.4, 6.14
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.2% (16th percentile)
- NVD status
- Modified
- Published
- 2025-03-07
CVE-2025-21836 at NVD
No indexed exploits for CVE-2025-21836 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-21836 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.