CVE-2021-21781
Linux Kernel vulnerability analysis and mitigation

Overview

An information disclosure vulnerability exists in the ARM SIGPAGE functionality of Linux Kernel v5.4.66 and v5.4.54. The vulnerability was discovered in January 2021 and patched in February 2021. The vulnerability affects Linux Kernel versions 5.4.54, 5.4.66, and up to version 5.11-rc4. This issue was fixed in kernel releases: 4.14.222, 4.19.177, 5.4.99, 5.10.17, and 5.11 (Talos Advisory).

Technical details

The vulnerability exists in the ARM SIGPAGE functionality where uninitialized memory is exposed to userland processes. When the kernel initializes the signal page using getsignalpage(), it allocates a page of memory using allocpages(GFPKERNEL, 0) but does not zero the memory before use. While a portion of this page is used to store signal handler instructions, the remaining uninitialized memory can contain kernel data. The vulnerability has a CVSS v3.1 base score of 3.3 (LOW) with vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N (NVD).

Impact

Any userland process can read the [sigpage] mapping within their own virtual memory space to leak kernel data. The leaked data persists until the device reboots. The contents of this page depend on the device itself and may potentially contain data from a previous boot if the device is not shut down for too long (Talos Advisory).

Mitigation and workarounds

The vulnerability was fixed in kernel releases 4.14.222, 4.19.177, 5.4.99, 5.10.17, and 5.11. Users should upgrade to these or later versions to mitigate the vulnerability (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40205HIGH7.8
  • Linux KernelLinux Kernel
  • linux-gcp-5.4
NoYesNov 12, 2025
CVE-2025-40211HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-6.8
NoYesNov 21, 2025
CVE-2025-40206MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules-extra
NoYesNov 12, 2025
CVE-2025-40210MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules
NoYesNov 21, 2025
CVE-2025-40212N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesNov 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management