CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-21988

Critical · CVSS 9.8
CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
NVD-CWE-noinfo

Description

In the Linux kernel, the following vulnerability has been resolved: fs/netfs/read_collect: add to next->prev_donated If multiple subrequests donate data to the same "next" request (depending on the subrequest completion order), each of them would overwrite the `prev_donated` field, causing data corruption and a BUG() crash ("Can't donate prior to front").

Affected packages

Linux Kernel 6.12.0 → 6.12.20
Linux Kernel 6.13.0 → 6.13.8

References

Status: profiled · ingested 2026-07-30T12:00:00.000Z