SB2025031273 - Resource management error in Linux kernel mm
Published: March 12, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2025-21861)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the migrate_device_finalize() function in mm/migrate_device.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/069dd21ea8262204f94737878389c2815a054a9e
- https://git.kernel.org/stable/c/3f9240d59e9a95d19f06120bfd1d0e681c6c0ac7
- https://git.kernel.org/stable/c/41cddf83d8b00f29fd105e7a0777366edc69a5cf
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.17
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.5
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14