SB2025032736 - Use-after-free in Linux kernel overlayfs
Published: March 27, 2025 Updated: May 11, 2025
Security Bulletin ID
SB2025032736
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use-after-free (CVE-ID: CVE-2025-21887)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the ovl_link_up() function in fs/overlayfs/copy_up.c. A local user can escalate privileges on the system.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3594aad97e7be2557ca9fa9c931b206b604028c8
- https://git.kernel.org/stable/c/4b49d939b5a79117f939b77cc67efae2694d9799
- https://git.kernel.org/stable/c/60b4b5c1277fc491da9e1e7abab307bfa39c2db7
- https://git.kernel.org/stable/c/64455c8051c3aedc71abb7ec8d47c80301f99f00
- https://git.kernel.org/stable/c/a7c41830ffcd17b2177a95a9b99b270302090c35
- https://git.kernel.org/stable/c/c84e125fff2615b4d9c259e762596134eddd2f27
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.179
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.130
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.18
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.6
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.81