Answer in brief
CVE-2025-21767 records a Unknown severity vulnerability in clocksource: Use migrate_disable() to avoid calling get_random_u32() in atomic context. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=d9b40ebd448e437ffbc65f013836f98252279a82 <d9c217fadfcff7a8df58567517d1e4253f3fd243 || >=7560c02bdffb7c52d1457fa551b9e745d4b9e754 <60f54f0d4ea530950549a8263e6fdd70a40490a4 || >=7560c02bdffb7c52d1457fa551b9e745d4b9e754 <852805b6cbdb69c298a8fc9fbe79994c95106e04 || >=7560c02bdffb7c52d1457fa551b9e745d4b9e754 <8783ceeee797d9aa9cfe150690fb9d0bac8cc459 || >=7560c02bdffb7c52d1457fa551b9e745d4b9e754 <cc3d79e7c806cb57d71c28a4a35e7d7fb3265faa || >=7560c02bdffb7c52d1457fa551b9e745d4b9e754 <0fb534187d2355f6c8f995321e76d1ccd1262ac1 || >=7560c02bdffb7c52d1457fa551b9e745d4b9e754 <6bb05a33337b2c842373857b63de5c9bf1ae2a09 || 193e14e68e907b2a7a936a7726accbaa4df25a4d || 155d3c5d24ee13cafa6236b49fc02b240a511d59 || >=5.10.50 <5.10.235 || >=5.12.17 <5.13 || >=5.13.2 <5.14 | d9c217fadfcff7a8df58567517d1e4253f3fd243, 60f54f0d4ea530950549a8263e6fdd70a40490a4, 852805b6cbdb69c298a8fc9fbe79994c95106e04, 8783ceeee797d9aa9cfe150690fb9d0bac8cc459, cc3d79e7c806cb57d71c28a4a35e7d7fb3265faa, 0fb534187d2355f6c8f995321e76d1ccd1262ac1, 6bb05a33337b2c842373857b63de5c9bf1ae2a09, 5.10.235, 5.13, 5.14 |
| Linux/Linuxgeneric | 5.14 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.5 <* | * |
Published upstream
Feb 27, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Jul 14, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 6, 2026
In the Linux kernel, the following vulnerability has been resolved: clocksource: Use migrate_disable() to avoid calling get_random_u32() in atomic context The following bug report happened with a PREEMPT_RT kernel: BUG: sleeping function called from invalid context at kernel/locking/spinlock_rt.c:48 in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 2012, name: kwatchdog preempt_count: 1, expected: 0 RCU nest depth: 0, expected: 0 get_random_u32+0x4f/0x110 clocksource_verify_choose_cpus+0xab/0x1a0 clocksource_verify_percpu.part.0+0x6b/0x330 clocksource_watchdog_kthread+0x193/0x1a0 It is due to the fact that clocksource_verify_choose_cpus() is invoked with preemption disabled. This function invokes get_random_u32() to obtain random numbers for choosing CPUs. The batched_entropy_32 local lock and/or the base_crng.lock spinlock in driver/char/random.c will be acquired during the call. In PREEMPT_RT kernel, they are both sleeping locks and so cannot be acquired in atomic context. Fix this problem by using migrate_disable() to allow smp_processor_id() to be reliably used without introducing atomic context. preempt_disable() is then called after clocksource_verify_choose_cpus() but before the clocksource measurement is being run to avoid introducing unexpected latency.
Quoted source text, attributed separately from HOL analysis.