Review reviewHigh

CVE-2025-21731

Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP

In the Linux kernel, the following vulnerability has been resolved: nbd: don't allow reconnect after disconnect Following process can cause nbd_config UAF: 1) grab nbd_config temporarily; 2) nbd_genl_disconnect() flush all recv_work() and release the initial reference: nbd_genl_disconnect nbd_disconnect_and_put nbd_disconnect flush_workqueue(nbd->recv_workq) if (test_and_clear_bit(NBD_RT_HAS_CONFIG_REF, ...)) nbd_config_put -> due to step 1), reference is still not zero 3) nbd_genl_reconfigure() queue recv_work() again; nbd_genl_reconfigure config = nbd_get_config_unlocked(nbd) if (!config)...

CVSS
7.8
EPSS
0.22%
13.1% percentile
CISA KEV
Not listed
Published
2025.02.27
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.22%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: nbd: don't allow reconnect after disconnect Following process can cause nbd_config UAF: 1) grab nbd_config temporarily; 2) nbd_genl_disconnect() flush all recv_work() and release the initial reference: nbd_genl_disconnect nbd_disconnect_and_put nbd_disconnect flush_workqueue(nbd->recv_workq) if (test_and_clear_bit(NBD_RT_HAS_CONFIG_REF, ...)) nbd_config_put -> due to step 1), reference is still not zero 3) nbd_genl_reconfigure() queue recv_work() again; nbd_genl_reconfigure config = nbd_get_config_unlocked(nbd) if (!config)...

Affected product and versions

Product
Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
Affected versions
>= b7aa3d39385dc2d95899f9e379623fef446a2acd < e70a578487a47d7cf058904141e586684d1c3381, >= b7aa3d39385dc2d95899f9e379623fef446a2acd < 6bef6222a3f6c7adb6396f77f25a3579d821b09a, >= b7aa3d39385dc2d95899f9e379623fef446a2acd < e3be8862d73cac833e0fb7602636c19c6cb94b11, >= b7aa3d39385dc2d95899f9e379623fef446a2acd < e7343fa33751cb07c1c56b666bf37cfca357130e, >= b7aa3d39385dc2d95899f9e379623fef446a2acd < d208d2c52b652913b5eefc8ca434b0d6b757f68f, >= b7aa3d39385dc2d95899f9e379623fef446a2acd < a8ee6ecde2b7bfb58c8a3afe8a9d2b848f580739, >= b7aa3d39385dc2d95899f9e379623fef446a2acd < 9793bd5ae4bdbdb2dde401a3cab94a6bfd05e302, >= b7aa3d39385dc2d95899f9e379623fef446a2acd < 844b8cdc681612ff24df62cdefddeab5772fadf1, >= 4.12, >= V3.1.6, >= 4.12 < 5.4.291, >= 5.5 < 5.10.235, >= 5.11 < 5.15.179, >= 5.16 < 6.1.129, >= 6.2 < 6.6.76, >= 6.7 < 6.12.13, >= 6.13 < 6.13.2
Fixed versions
5.4.291, 5.10.235, 5.15.179, 6.1.129, 6.6.76, 6.12.13, 6.13.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, SIMATIC S7-1500 CPU 1518-4 PN/DP MFP, SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-416