Answer in brief
CVE-2025-21726 records a Unknown severity vulnerability in padata: avoid UAF for reorder_work. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-21726 records a Unknown severity vulnerability in padata: avoid UAF for reorder_work. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bbefa1dd6a6d53537c11624752219e39959d04fb <f4f1b1169fc3694f9bc3e28c6c68dbbf4cc744c0 || >=bbefa1dd6a6d53537c11624752219e39959d04fb <4c6209efea2208597dbd3e52dc87a0d1a8f2dbe1 || >=bbefa1dd6a6d53537c11624752219e39959d04fb <7000507bb0d2ceb545c0a690e0c707c897d102c2 || >=bbefa1dd6a6d53537c11624752219e39959d04fb <6f45ef616775b0ce7889b0f6077fc8d681ab30bc || >=bbefa1dd6a6d53537c11624752219e39959d04fb <8ca38d0ca8c3d30dd18d311f1a7ec5cb56972cac || >=bbefa1dd6a6d53537c11624752219e39959d04fb <a54091c24220a4cd847d5b4f36d678edacddbaf0 || >=bbefa1dd6a6d53537c11624752219e39959d04fb <dd7d37ccf6b11f3d95e797ebe4e9e886d0332600 || b4c8ed0bf977760a206997b6429a7ac91978f440 || e43d65719527043f1ef79ecba9d4ede58cbc7ffe || >=5.4.19 <5.5 || >=5.5.3 <5.6 | f4f1b1169fc3694f9bc3e28c6c68dbbf4cc744c0, 4c6209efea2208597dbd3e52dc87a0d1a8f2dbe1, 7000507bb0d2ceb545c0a690e0c707c897d102c2, 6f45ef616775b0ce7889b0f6077fc8d681ab30bc, 8ca38d0ca8c3d30dd18d311f1a7ec5cb56972cac, a54091c24220a4cd847d5b4f36d678edacddbaf0, dd7d37ccf6b11f3d95e797ebe4e9e886d0332600, 5.5, 5.6 |
| Linux/Linuxgeneric | 5.6 | Not reported |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
Published upstream
Feb 27, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: padata: avoid UAF for reorder_work Although the previous patch can avoid ps and ps UAF for _do_serial, it can not avoid potential UAF issue for reorder_work. This issue can happen just as below: crypto_request crypto_request crypto_del_alg padata_do_serial ... padata_reorder // processes all remaining // requests then breaks while (1) { if (!padata) break; ... } padata_do_serial // new request added list_add // sees the new request queue_work(reorder_work) padata_reorder queue_work_on(squeue->work) ... <kworker context> padata_serial_worker // completes new request, // no more outstanding // requests crypto_del_alg // free pd <kworker context> invoke_padata_reorder // UAF of pd To avoid UAF for 'reorder_work', get 'pd' ref before put 'reorder_work' into the 'serial_wq' and put 'pd' ref until the 'serial_wq' finish.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=bbefa1dd6a6d53537c11624752219e39959d04fb <f4f1b1169fc3694f9bc3e28c6c68dbbf4cc744c0 || >=bbefa1dd6a6d53537c11624752219e39959d04fb <4c6209efea2208597dbd3e52dc87a0d1a8f2dbe1 || >=bbefa1dd6a6d53537c11624752219e39959d04fb <7000507bb0d2ceb545c0a690e0c707c897d102c2 || >=bbefa1dd6a6d53537c11624752219e39959d04fb <6f45ef616775b0ce7889b0f6077fc8d681ab30bc || >=bbefa1dd6a6d53537c11624752219e39959d04fb <8ca38d0ca8c3d30dd18d311f1a7ec5cb56972cac || >=bbefa1dd6a6d53537c11624752219e39959d04fb <a54091c24220a4cd847d5b4f36d678edacddbaf0 || >=bbefa1dd6a6d53537c11624752219e39959d04fb <dd7d37ccf6b11f3d95e797ebe4e9e886d0332600 || b4c8ed0bf977760a206997b6429a7ac91978f440 || e43d65719527043f1ef79ecba9d4ede58cbc7ffe || >=5.4.19 <5.5 || >=5.5.3 <5.6 | f4f1b1169fc3694f9bc3e28c6c68dbbf4cc744c0, 4c6209efea2208597dbd3e52dc87a0d1a8f2dbe1, 7000507bb0d2ceb545c0a690e0c707c897d102c2, 6f45ef616775b0ce7889b0f6077fc8d681ab30bc, 8ca38d0ca8c3d30dd18d311f1a7ec5cb56972cac, a54091c24220a4cd847d5b4f36d678edacddbaf0, dd7d37ccf6b11f3d95e797ebe4e9e886d0332600, 5.5, 5.6 |
| Linux/Linuxgeneric | 5.6 | Not reported |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
Published upstream
Feb 27, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: padata: avoid UAF for reorder_work Although the previous patch can avoid ps and ps UAF for _do_serial, it can not avoid potential UAF issue for reorder_work. This issue can happen just as below: crypto_request crypto_request crypto_del_alg padata_do_serial ... padata_reorder // processes all remaining // requests then breaks while (1) { if (!padata) break; ... } padata_do_serial // new request added list_add // sees the new request queue_work(reorder_work) padata_reorder queue_work_on(squeue->work) ... <kworker context> padata_serial_worker // completes new request, // no more outstanding // requests crypto_del_alg // free pd <kworker context> invoke_padata_reorder // UAF of pd To avoid UAF for 'reorder_work', get 'pd' ref before put 'reorder_work' into the 'serial_wq' and put 'pd' ref until the 'serial_wq' finish.
Quoted source text, attributed separately from HOL analysis.