CVE-2025-21669: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: discard packets if the transport changes If the socket has been de-assigned or assigned to another transport, we must discard any packets received because they are not expected and would cause issues when we access vsk->transport. A possible scenario is described by Hyunwoo Kim in the attached link, where after a first connect() interrupted by a signal, and a second connect() failed, we can find `vsk->transport` at NULL, leading to a NULL pointer dereference.

Affected products

  • Linux Linux Kernel: from 5.5, before 5.15.177 (fixed in 5.15.177); from 5.16, before 6.1.127 (fixed in 6.1.127); from 6.2, before 6.6.74 (fixed in 6.6.74); from 6.7, before 6.12.11 (fixed in 6.12.11); version 6.13 only

Published 2025-01-31. Last modified 2026-07-30.