CVE-2025-21718: net: rose: fix timer races against user threads
In the Linux kernel, the following vulnerability has been resolved:
net: rose: fix timer races against user threads
Rose timers only acquire the socket spinlock, without
checking if the socket is owned by one user thread.
Add a check and rearm the timers if needed.
BUG: KASAN: slab-use-after-free in rose_timer_expiry+0x31d/0x360 net/rose/rose_timer.c:174
Read of size 2 at addr ffff88802f09b82a by task swapper/0/0
CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 6.13.0-rc5-syzkaller-00172-gd1bf27c4e176 #0
Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024
Call Trace:
<IRQ>
__dump_stack lib/dump_stack.c:94 [inline]
dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120
print_address_description mm/kasan/report.c:378 [inline]
print_report+0x169/0x550 mm/kasan/report.c:489
kasan_report+0x143/0x180 mm/kasan/report.c:602
rose_timer_expiry+0x31d/0x360 net/rose/rose_timer.c:174
call_timer_fn+0x187/0x650 kernel/time/timer.c:1793
expire_timers kernel/time/timer.c:1844 [inline]
__run_timers kernel/time/timer.c:2418 [inline]
__run_timer_base+0x66a/0x8e0 kernel/time/timer.c:2430
run_timer_base kernel/time/timer.c:2439 [inline]
run_timer_softirq+0xb7/0x170 kernel/time/timer.c:2449
handle_softirqs+0x2d4/0x9b0 kernel/softirq.c:561
__do_softirq kernel/softirq.c:595 [inline]
invoke_softirq kernel/softirq.c:435 [inline]
__irq_exit_rcu+0xf7/0x220 kernel/softirq.c:662
irq_exit_rcu+0x9/0x30 kernel/softirq.c:678
instr_sysvec_apic_timer_interrupt arch/x86/kernel/apic/apic.c:1049 [inline]
sysvec_apic_timer_interrupt+0xa6/0xc0 arch/x86/kernel/apic/apic.c:1049
</IRQ>
Security readout for executives and security teams
Plain-English summary
A race in the Linux kernel’s ROSE networking timers can access memory after it has been freed. A local, low-privileged user may be able to trigger serious confidentiality, integrity, or availability impact. Exposure depends on the installed kernel and whether ROSE networking is present and accessible.
Executive priority
Treat this as a high-priority kernel maintenance issue on multi-user or locally accessible Linux systems. Patch through supported vendor channels promptly, while validating actual exposure before emergency disruption. Internet exposure alone does not establish exploitability because the supplied vector requires local access.
Technical view
ROSE timer callbacks lock the socket but previously did not check whether a user thread owned it. Concurrent timer and user-thread activity can cause a slab use-after-free in rose_timer_expiry. The supplied CVSS 3.1 score is 7.8: local, low-complexity, low-privilege, no user interaction, with potentially high impact.
Likely exposure
Potentially exposed assets are Linux systems running the affected kernel versions or lines identified in the CVE data, particularly multi-user systems where low-privileged local users can reach ROSE functionality. The bundle does not establish that every distribution kernel with a matching version is vulnerable; vendor backports may change status.
Exploitation context
The supplied record is not marked as KEV, and the sources provide no evidence of active exploitation. The demonstrated failure came from syzkaller with KASAN and produced a kernel use-after-free. CVSS characterizes exploitation as local with low privileges; remote exploitability is not supported by the bundle.
Researcher notes
The evidence confirms a timer-versus-user-thread race and KASAN-detected slab use-after-free at rose_timer_expiry. Multiple stable commits indicate fixes across kernel branches. The bundle provides neither a CWE assignment nor evidence of public or active exploitation. Distribution package status should take precedence over simple upstream version matching because fixes may be backported.
Mitigation direction
Install the distribution or vendor kernel update incorporating the applicable Linux stable fix.
Reboot affected systems into the updated kernel and confirm the running version changed.
Prioritize shared or multi-user hosts where untrusted local accounts exist.
If updates are unavailable, obtain product-specific mitigation guidance from the Linux distributor or appliance vendor.
Validation and detection
Inventory running kernel versions across Linux servers, endpoints, appliances, and embedded systems.
Confirm whether ROSE networking is present and accessible on each potentially affected host.
Compare vendor package status with the CVE record and applicable stable-kernel fix.
Verify the patched kernel is running after reboot, not merely installed.
Review kernel crash telemetry for rose_timer_expiry or slab-use-after-free indicators.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-21718 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
2ADP providers
12Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.