
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-21874 is a vulnerability discovered in the Linux kernel's dm-integrity component, specifically affecting the table status functionality in Inline mode. The vulnerability was disclosed on March 27, 2025. The issue occurs when the journal is unused and journal_sectors is zero in Inline mode, leading to a potential divide by zero condition (NVD Database, Red Hat Security).
The vulnerability manifests when calculating the journal watermark in Inline mode, where journal_sectors is zero and the journal is unused. When attempting to divide by journal_sectors without proper validation, it triggers a divide by zero error. The vulnerability has been assigned a CVSS v3.1 score of 5.5 with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating a moderate severity level (Red Hat Security).
When exploited, this vulnerability can cause a system crash through an OOPS error. On affected systems, particularly 32-bit testing machines, the vulnerability reliably crashes with a divide error: 0000 [#1] PREEMPT SMP error, affecting the CPU 0 with PID 2450 in the dmsetup process (NVD Database).
The vulnerability can be triggered through a simple table query using the dmsetup command. The issue appears to be more reliably reproducible on 32-bit systems, though its manifestation may vary depending on compiler optimization (NVD Database).
Red Hat has acknowledged the vulnerability and marked it as 'Fix deferred' for Red Hat Enterprise Linux 9 and kernel-rt packages. Other versions of Red Hat Enterprise Linux (6, 7, and 8) are not affected by this vulnerability (Red Hat Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."