Answer in brief
CVE-2025-21919 records a High severity (CVSS 7.8) vulnerability in sched/fair: Fix potential memory corruption in child_cfs_rq_on_list. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-21919 records a High severity (CVSS 7.8) vulnerability in sched/fair: Fix potential memory corruption in child_cfs_rq_on_list. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=fdaba61ef8a268d4136d0a113d153f7a89eb9984 <5cb300dcdd27e6a351ac02541e0231261c775852 || >=fdaba61ef8a268d4136d0a113d153f7a89eb9984 <000c9ee43928f2ce68a156dd40bab7616256f4dd || >=fdaba61ef8a268d4136d0a113d153f7a89eb9984 <9cc7f0018609f75a349e42e3aebc3b0e905ba775 || >=fdaba61ef8a268d4136d0a113d153f7a89eb9984 <b5741e4b9ef3567613b2351384f91d3f16e59986 || >=fdaba61ef8a268d4136d0a113d153f7a89eb9984 <e1dd09df30ba86716cb2ffab97dc35195c01eb8f || >=fdaba61ef8a268d4136d0a113d153f7a89eb9984 <3b4035ddbfc8e4521f85569998a7569668cccf51 | 5cb300dcdd27e6a351ac02541e0231261c775852, 000c9ee43928f2ce68a156dd40bab7616256f4dd, 9cc7f0018609f75a349e42e3aebc3b0e905ba775, b5741e4b9ef3567613b2351384f91d3f16e59986, e1dd09df30ba86716cb2ffab97dc35195c01eb8f, 3b4035ddbfc8e4521f85569998a7569668cccf51 |
| Linux/Linuxgeneric | 5.13 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Published upstream
Apr 1, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 14, 2026
In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix potential memory corruption in child_cfs_rq_on_list child_cfs_rq_on_list attempts to convert a 'prev' pointer to a cfs_rq. This 'prev' pointer can originate from struct rq's leaf_cfs_rq_list, making the conversion invalid and potentially leading to memory corruption. Depending on the relative positions of leaf_cfs_rq_list and the task group (tg) pointer within the struct, this can cause a memory fault or access garbage data. The issue arises in list_add_leaf_cfs_rq, where both cfs_rq->leaf_cfs_rq_list and rq->leaf_cfs_rq_list are added to the same leaf list. Also, rq->tmp_alone_branch can be set to rq->leaf_cfs_rq_list. This adds a check `if (prev == &rq->leaf_cfs_rq_list)` after the main conditional in child_cfs_rq_on_list. This ensures that the container_of operation will convert a correct cfs_rq struct. This check is sufficient because only cfs_rqs on the same CPU are added to the list, so verifying the 'prev' pointer against the current rq's list head is enough. Fixes a potential memory corruption issue that due to current struct layout might not be manifesting as a crash but could lead to unpredictable behavior when the layout changes.
Quoted source text, attributed separately from HOL analysis.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFP (generic), Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=fdaba61ef8a268d4136d0a113d153f7a89eb9984 <5cb300dcdd27e6a351ac02541e0231261c775852 || >=fdaba61ef8a268d4136d0a113d153f7a89eb9984 <000c9ee43928f2ce68a156dd40bab7616256f4dd || >=fdaba61ef8a268d4136d0a113d153f7a89eb9984 <9cc7f0018609f75a349e42e3aebc3b0e905ba775 || >=fdaba61ef8a268d4136d0a113d153f7a89eb9984 <b5741e4b9ef3567613b2351384f91d3f16e59986 || >=fdaba61ef8a268d4136d0a113d153f7a89eb9984 <e1dd09df30ba86716cb2ffab97dc35195c01eb8f || >=fdaba61ef8a268d4136d0a113d153f7a89eb9984 <3b4035ddbfc8e4521f85569998a7569668cccf51 | 5cb300dcdd27e6a351ac02541e0231261c775852, 000c9ee43928f2ce68a156dd40bab7616256f4dd, 9cc7f0018609f75a349e42e3aebc3b0e905ba775, b5741e4b9ef3567613b2351384f91d3f16e59986, e1dd09df30ba86716cb2ffab97dc35195c01eb8f, 3b4035ddbfc8e4521f85569998a7569668cccf51 |
| Linux/Linuxgeneric | 5.13 | Not reported |
| Siemens/SIMATIC S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIMATIC S7-1500 CPU 1518F-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
| Siemens/SIPLUS S7-1500 CPU 1518-4 PN/DP MFPgeneric | >=V3.1.6 <* | * |
Published upstream
Apr 1, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Jul 14, 2026
In the Linux kernel, the following vulnerability has been resolved: sched/fair: Fix potential memory corruption in child_cfs_rq_on_list child_cfs_rq_on_list attempts to convert a 'prev' pointer to a cfs_rq. This 'prev' pointer can originate from struct rq's leaf_cfs_rq_list, making the conversion invalid and potentially leading to memory corruption. Depending on the relative positions of leaf_cfs_rq_list and the task group (tg) pointer within the struct, this can cause a memory fault or access garbage data. The issue arises in list_add_leaf_cfs_rq, where both cfs_rq->leaf_cfs_rq_list and rq->leaf_cfs_rq_list are added to the same leaf list. Also, rq->tmp_alone_branch can be set to rq->leaf_cfs_rq_list. This adds a check `if (prev == &rq->leaf_cfs_rq_list)` after the main conditional in child_cfs_rq_on_list. This ensures that the container_of operation will convert a correct cfs_rq struct. This check is sufficient because only cfs_rqs on the same CPU are added to the list, so verifying the 'prev' pointer against the current rq's list head is enough. Fixes a potential memory corruption issue that due to current struct layout might not be manifesting as a crash but could lead to unpredictable behavior when the layout changes.
Quoted source text, attributed separately from HOL analysis.