CVE-2025-21811·Kernel vulnerability
In the Linux kernel, the following vulnerability has been resolved: nilfs2: protect access to buffers with no active references nilfs_lookup_dirty_data_buffers(), which iterates through the buffers attached to dirty data folios/pages, accesses the attached buffers without locking the folios/pages. For data cache, nilfs_clear_folio_dirty() may be called asynchronously when the file system degenerates to read only, so nilfs_lookup_dirty_data_buffers() still has the potential to cause use after free issues when buffers lose the protection of their dirty state midway due to this asynchronous clearing and are unintentionally freed by try_to_free_buffers(). Eliminate this race issue by adjusting the lock section in this function.
- Severity
- high
- Software
- Kernel
- Fixed in
- 6.13.2
- Published
- 2025-02-27
Affected versions
From: 6.13
Until: 6.13.2
Fixed in: 6.13.2
How to fix this CVE
Update your Linux kernel to version 6.13.2 or later to resolve a race condition in the nilfs2 filesystem that could lead to use-after-free vulnerabilities. This patch strengthens buffer access protections during asynchronous read-only transitions, preventing potential memory corruption. Apply the kernel update and reboot your system to fully implement the security fix.
sudo dnf update kernel kernel-develDefensia detects this vulnerability
How to check if you are affected
- Step 1: Check current kernel version with: uname -r (vulnerable if output shows 6.13.0, 6.13.1, or 6.13.2-rc versions)
- Step 2: Verify nilfs2 filesystem usage with: grep nilfs2 /proc/filesystems && mount | grep nilfs2 (if no output, nilfs2 is not in use on this system)
- Step 3: Monitor kernel logs for use-after-free errors with: sudo journalctl -k | grep -i 'use.after.free\|page.already.pinned\|buffer.freeing'
- Step 4: After patching, confirm the new kernel version with: uname -r (should show 6.13.2 or later)
FAQ
What is CVE-2025-21811?
CVE-2025-21811 is a race condition in the Linux kernel's nilfs2 filesystem implementation where buffer access is not properly synchronized with folio locks, allowing use-after-free when the filesystem transitions to read-only mode asynchronously.
Is CVE-2025-21811 being actively exploited?
No, CVE-2025-21811 is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and no public exploits have been released.
What versions of Kernel are affected by CVE-2025-21811?
Linux kernel versions 6.13.0 through 6.13.2 are affected. The vulnerability is fixed in kernel version 6.13.2 and later stable releases.
How do I check if my server is vulnerable to CVE-2025-21811?
Run 'uname -r' to check your kernel version. If the output is 6.13.0 or 6.13.1, you are vulnerable. Additionally, confirm nilfs2 is in use with 'mount | grep nilfs2' since the vulnerability only affects systems using this filesystem.
Does Defensia detect CVE-2025-21811?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Linux kernel is installed on a monitored server, CVE-2025-21811 will appear in your dashboard with remediation steps.
Related Kernel CVEs
References
- https://git.kernel.org/stable/c/367a9bffabe08c04f6d725032cce3d891b2b9e1a
- https://git.kernel.org/stable/c/4b08d23d7d1917bef4fbee8ad81372f49b006656
- https://git.kernel.org/stable/c/58c27fa7a610b6e8d44e6220e7dbddfbaccaf439
- https://git.kernel.org/stable/c/72cf688d0ce7e642b12ddc9b2a42524737ec1b4a
- https://git.kernel.org/stable/c/8e1b9201c9a24638cf09c6e1c9f224157328010b
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-21811. Free for 1 server.
Get started free