CVE-2025-21893: keys: Fix UAF in key_put()
In the Linux kernel, the following vulnerability has been resolved:
keys: Fix UAF in keyput()
Once a key's reference count has been reduced to 0, the garbage collector thread may destroy it at any time and so keyput() is not allowed to touch the key after that point. The most keyput() is normally allowed to do is to touch keygcwork as that's a static global variable.
However, in an effort to speed up the reclamation of quota, this is now done in keyput() once the key's usage is reduced to 0 - but now the code is looking at the key after the deadline, which is forbidden.
Fix this by using a flag to indicate that a key can be gc'd now rather than looking at the key's refcount in the garbage collector.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21893?
CVE-2025-21893 is classified as a high-severity vulnerability impacting the Linux kernel.
How do I fix CVE-2025-21893?
To fix CVE-2025-21893, update your Linux kernel to the latest patched version provided by your distribution.
What systems are affected by CVE-2025-21893?
CVE-2025-21893 affects various versions of the Linux kernel used in many Linux distributions.
What type of vulnerability is CVE-2025-21893?
CVE-2025-21893 is a use-after-free (UAF) vulnerability in the key management feature of the Linux kernel.
What are the potential risks of CVE-2025-21893?
Exploitation of CVE-2025-21893 may lead to arbitrary code execution or system crashes.