Improper locking in Linux kernel - CVE-2025-21900
Published: April 2, 2025 / Updated: May 11, 2025
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper locking within the nfs4_atomic_open() function in fs/nfs/nfs4proc.c, within the nfs4_inode_return_delegation() function in fs/nfs/delegation.c. A local user can perform a denial of service (DoS) attack.
Affected software
Ubuntu
linux (Ubuntu package)
linux-aws (Ubuntu package)
linux-lowlatency (Ubuntu package)
How to mitigate CVE-2025-21900
linux (Ubuntu package) - addressed in versions 6.11.0-26.26, 6.11.0-26.26~24.04.1, 6.11.0-1010.10, 6.11.0-1013.13, 6.11.0-1015.15, 6.11.0-1015.15~24.04.1, 6.11.0-1022.22
linux-aws (Ubuntu package) - update to 6.11.0-1014.15
linux-lowlatency (Ubuntu package) - addressed in versions 6.11.0-1014.15, 6.11.0-1014.15~24.04.1, 6.11.0-1016.17