Junglewise Threat Intelligence

CVE-2025-21761: Linux Kernel use-after-free in Open vSwitch ovs_vport_cmd_fill_info

CVE-2025-21761 · Severity: high · CVSS 7.8 · Published 2025-02-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's Open vSwitch component, which is used to manage virtual network switching. A local attacker could exploit this flaw to cause a system crash or potentially execute unauthorized code by triggering a 'use-after-free' error during network port operations. This could lead to a full compromise of the affected system's availability and data integrity.

Technical details

A use-after-free (UAF) vulnerability exists in the Open vSwitch implementation within the Linux kernel. The function 'ovs_vport_cmd_fill_info()' could be invoked without proper RTNL (Routing Netlink) or RCU (Read-Copy-Update) protection when accessing network namespace information. This lack of synchronization allows a local attacker to trigger a race condition where network structures are accessed after being freed. An attacker can exploit this to achieve arbitrary code execution or cause a kernel panic. The issue has been resolved by implementing RCU protection and using 'dev_net_rcu()' to safely access the network namespace.

Affected products

  • Linux Linux Kernel 4.15 to 5.4.291, 5.5 to 5.10.235, 5.11 to 5.15.179, 5.16 to 6.1.129, 6.2 to 6.6.79, 6.7 to 6.12.16, 6.13 to 6.13.4

Timeline

  • 2025-02-07: other: Patch authored
  • 2025-02-26: disclosed: CVE published by kernel.org
  • 2025-02-27: advisory: NVD publication date

References

Related threats