CVE-2025-21749: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: net: rose: lock the socket in rose_bind() syzbot reported a soft lockup in rose_loopback_timer(), with a repro calling bind() from multiple threads. rose_bind() must lock the socket to avoid this issue.
Affected products
- Linux Linux Kernel: from 2.6.12, before 6.1.129 (fixed in 6.1.129); from 6.2, before 6.6.78 (fixed in 6.6.78); from 6.7, before 6.12.14 (fixed in 6.12.14); from 6.13, before 6.13.3 (fixed in 6.13.3); version 6.14 only
Published 2025-02-27. Last modified 2026-06-17.