In the Linux kernel, the following vulnerability has been resolved:
zram: fix potential UAF of zram table
If zrammetaalloc failed early, it frees allocated zram->table without setting it NULL. Which will potentially cause zrammetafree to access the table if user reset an failed and uninitialized device.
[
{
"digest": {
"length": 533.0,
"function_hash": "28591253271867399981984648283640472045"
},
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "zram_meta_alloc",
"file": "drivers/block/zram/zram_drv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@212fe1c0df4a150fb6298db2cfff267ceaba5402",
"id": "CVE-2025-21671-0d45f11a",
"signature_type": "Function"
},
{
"digest": {
"line_hashes": [
"333382010484989274237413131536836355452",
"46045155742550784059022152260082092643",
"308819822850004835486949237070413461793",
"175705271587799910650959746358922761991"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "drivers/block/zram/zram_drv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@902ef8f16d5ca77edc77c30656be54186c1e99b7",
"id": "CVE-2025-21671-25683817",
"signature_type": "Line"
},
{
"digest": {
"line_hashes": [
"333382010484989274237413131536836355452",
"46045155742550784059022152260082092643",
"308819822850004835486949237070413461793",
"175705271587799910650959746358922761991"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"target": {
"file": "drivers/block/zram/zram_drv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@212fe1c0df4a150fb6298db2cfff267ceaba5402",
"id": "CVE-2025-21671-531993ee",
"signature_type": "Line"
},
{
"digest": {
"length": 533.0,
"function_hash": "28591253271867399981984648283640472045"
},
"deprecated": false,
"signature_version": "v1",
"target": {
"function": "zram_meta_alloc",
"file": "drivers/block/zram/zram_drv.c"
},
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@902ef8f16d5ca77edc77c30656be54186c1e99b7",
"id": "CVE-2025-21671-868fdb00",
"signature_type": "Function"
}
]