CVE-2025-21875
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-21875 affects the Linux kernel's MPTCP (Multipath TCP) implementation, specifically related to address removal handling under MSK socket lock. The vulnerability was discovered on March 27, 2025, when Syzkaller reported a lockdep splat in the PM control path (NVD).

Technical details

The vulnerability manifests as a race condition where the PM (Path Manager) can attempt to send a RMADDR over an MSK socket without first acquiring the MSK socket lock. This issue stems from an optimization where RMADDR notifications were not sent when there were no subflows. However, this optimization proved problematic as without proper locks, another process could cause concurrent access issues (NVD).

Impact

The vulnerability could lead to race conditions in the MPTCP implementation, potentially affecting network stability and reliability. The issue specifically impacts the address removal functionality in the MPTCP path management system (NVD).

Mitigation and workarounds

The vulnerability has been resolved in the Linux kernel by ensuring proper handling of address removal under MSK socket lock. The fix involves correcting the assumption about RM_ADDR notifications when there are no subflows (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40205HIGH7.8
  • Linux KernelLinux Kernel
  • linux-gcp-5.4
NoYesNov 12, 2025
CVE-2025-40211HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-6.8
NoYesNov 21, 2025
CVE-2025-40206MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules-extra
NoYesNov 12, 2025
CVE-2025-40210MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules
NoYesNov 21, 2025
CVE-2025-40212N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesNov 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management