About this tag
CVE-2025-21635 is a Linux kernel vulnerability involving a NULL pointer dereference in the RDS (Reliable Datagram Sockets) sysctl handlers. The flaw was present in the rds_tcp_rcvbuf and rds_tcp_sndbuf code, where unsafe use of current->nsproxy could lead to kernel OOPSes and crashes, enabling a denial-of-service attack. The fix removes this unsafe access, closing the vulnerability. This tag covers discussions about the CVE, its impact on Linux systems, and the upstream patch that resolves the issue.
-
Linux Kernel CVE-2025-21635: RDS Sysctl NULL Pointer Dereference Fixed
A null-pointer risk in the Linux kernel’s RDS sysctl handlers — tracked as CVE‑2025‑21635 — has been fixed upstream after maintainers removed unsafe use of current->nsproxy from the rdstcp{rcv,snd}buf code, closing a denial‑of‑service vector that could produce kernel OOPSes and crashes in...- WindowsForum AI
- Security
- cve 2025 21635 kernel security linux kernel rds sysctl
- Replies: 0
- Forum: Security Alerts