CVE-2025-21988
A critical flaw in the Linux kernel can corrupt data and crash the system. The bug occurs when multiple subrequests donate data to the same request, overwriting a field and triggering a crash. The issue has been fixed in a kernel update.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, all versions before the fix, on any distribution that uses the kernel.
Real-world impact
An attacker could trigger a crash or data corruption, causing a denial of service and potential loss of data on the affected system.
Why this severity
The CVSS score of 9.8 reflects a network attack vector, low attack complexity, no privileges required, no user interaction, and full confidentiality, integrity, and availability impact.
What to do about it
- 01Update your Linux kernel to a version that includes the fix.
- 02Reboot the system to load the updated kernel.
NVD-referenced vendor advisory
Timeline
- Apr 2, 2025 · Apr 2, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 7d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.