Answer in brief
CVE-2025-21851 records a Unknown severity vulnerability in bpf: Fix softlockup in arena_map_free on 64k page kernel. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=317460317a02a1af512697e6e964298dedd8a163 <c1f3f3892d4526f18aaeffdb6068ce861e793ee3 || >=317460317a02a1af512697e6e964298dedd8a163 <787d556a3de447e70964a4bdeba9196f62a62b1e || >=317460317a02a1af512697e6e964298dedd8a163 <517e8a7835e8cfb398a0aeb0133de50e31cae32b | c1f3f3892d4526f18aaeffdb6068ce861e793ee3, 787d556a3de447e70964a4bdeba9196f62a62b1e, 517e8a7835e8cfb398a0aeb0133de50e31cae32b |
| Linux/Linuxgeneric | 6.9 | Not reported |
Published upstream
Mar 12, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix softlockup in arena_map_free on 64k page kernel On an aarch64 kernel with CONFIG_PAGE_SIZE_64KB=y, arena_htab tests cause a segmentation fault and soft lockup. The same failure is not observed with 4k pages on aarch64. It turns out arena_map_free() is calling apply_to_existing_page_range() with the address returned by bpf_arena_get_kern_vm_start(). If this address is not page-aligned the code ends up calling apply_to_pte_range() with that unaligned address causing soft lockup. Fix it by round up GUARD_SZ to PAGE_SIZE << 1 so that the division by 2 in bpf_arena_get_kern_vm_start() returns a page-aligned value.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-21851 records a Unknown severity vulnerability in bpf: Fix softlockup in arena_map_free on 64k page kernel. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=317460317a02a1af512697e6e964298dedd8a163 <c1f3f3892d4526f18aaeffdb6068ce861e793ee3 || >=317460317a02a1af512697e6e964298dedd8a163 <787d556a3de447e70964a4bdeba9196f62a62b1e || >=317460317a02a1af512697e6e964298dedd8a163 <517e8a7835e8cfb398a0aeb0133de50e31cae32b | c1f3f3892d4526f18aaeffdb6068ce861e793ee3, 787d556a3de447e70964a4bdeba9196f62a62b1e, 517e8a7835e8cfb398a0aeb0133de50e31cae32b |
| Linux/Linuxgeneric | 6.9 | Not reported |
Published upstream
Mar 12, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix softlockup in arena_map_free on 64k page kernel On an aarch64 kernel with CONFIG_PAGE_SIZE_64KB=y, arena_htab tests cause a segmentation fault and soft lockup. The same failure is not observed with 4k pages on aarch64. It turns out arena_map_free() is calling apply_to_existing_page_range() with the address returned by bpf_arena_get_kern_vm_start(). If this address is not page-aligned the code ends up calling apply_to_pte_range() with that unaligned address causing soft lockup. Fix it by round up GUARD_SZ to PAGE_SIZE << 1 so that the division by 2 in bpf_arena_get_kern_vm_start() returns a page-aligned value.
Quoted source text, attributed separately from HOL analysis.