Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2025-21949

7.8 · HIGH
Published Apr 1, 2025 linux EPSS 0.18% (8th pctl)

Overview

CVE-2025-21949 is a high-severity vulnerability affecting linux linux_kernel. It was published on April 1, 2025 and has a CVSS 3.1 base score of 7.8 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

LoongArch: Set hugetlb mmap base address aligned with pmd size

With ltp test case "testcases/bin/hugefork02", there is a dmesg error

report message such as:

kernel BUG at mm/hugetlb.c:5550!

Oops - BUG[#1]:

CPU: 0 UID: 0 PID: 1517 Comm: hugefork02 Not tainted 6.14.0-rc2+ #241

Hardware name: QEMU QEMU Virtual Machine, BIOS unknown 2/2/2022

pc 90000000004eaf1c ra 9000000000485538 tp 900000010edbc000 sp 900000010edbf940

a0 900000010edbfb00 a1 9000000108d20280 a2 00007fffe9474000 a3 00007ffff3474000

a4 0000000000000000 a5 0000000000000003 a6 00000000003cadd3 a7 0000000000000000

t0 0000000001ffffff t1 0000000001474000 t2 900000010ecd7900 t3 00007fffe9474000

t4 00007fffe9474000 t5 0000000000000040 t6 900000010edbfb00 t7 0000000000000001

t8 0000000000000005 u0 90000000004849d0 s9 900000010edbfa00 s0 9000000108d20280

s1 00007fffe9474000 s2 0000000002000000 s3 9000000108d20280 s4 9000000002b38b10

s5 900000010edbfb

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 5.19, < 6.13.7 Affected

Frequently Asked Questions

What is CVE-2025-21949?

CVE-2025-21949 is a high-severity vulnerability affecting linux linux_kernel. It was published on April 1, 2025 and has a CVSS 3.1 base score of 7.8 (HIGH).

How severe is CVE-2025-21949?

This vulnerability has a CVSS 3.1 base score of 7.8, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2025-21949?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2025-21949?

CyberStrike's AI-powered security agents can automatically detect CVE-2025-21949 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.