CVE-2025-21834
Last modified
CVE-2025-21834 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: seccomp: passthrough uretprobe systemcall without filtering When attaching uretprobes to processes running inside docker, the attached process is segfaulted when encountering the retprobe. The reason is that now that uretprobe is a system call the default seccomp filters in docker block it as they only allow a specific set of known syscalls. This is true for other userspace applications which use seccomp to control their syscall surface. Since uretprobe is a "kernel implementation detail" system call which is not used by userspace application code directly, it is impractical and there's very little point in forcing all userspace applications to explicitly allow it in order to avoid crashing tracked processes. Pass this systemcall through seccomp without depending on configuration. Note: uretprobe is currently only x86_64 and isn't expected to ever be supported in i386. [kees: minimized changes for easier backporting, tweaked commit log]. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: seccomp: passthrough uretprobe systemcall without filtering When attaching uretprobes to processes running inside docker, the attached process is segfaulted when encountering the retprobe. The reason is that now that uretprobe is a system call the default seccomp filters in docker block it as they only allow a specific set of known syscalls. This is true for other userspace applications which use seccomp to control their syscall surface. Since uretprobe is a "kernel implementation detail" system call which is not used by userspace application code directly, it is impractical and there's very little point in forcing all userspace applications to explicitly allow it in order to avoid crashing tracked processes. Pass this systemcall through seccomp without depending on configuration. Note: uretprobe is currently only x86_64 and isn't expected to ever be supported in i386. [kees: minimized changes for easier backporting, tweaked commit log]
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | >= 6.11, < 6.12.14 | — |
| Linux | Linux Kernel | >= 6.13, < 6.13.3 | — |
| Linux | Linux Kernel | 6.14 | Rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-21834?
How severe is CVE-2025-21834?
How do I fix CVE-2025-21834?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-21829In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-2183An insufficient certificate validation issue in the Palo Alt…5.3
- CVE-2025-21830In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21831In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21832In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21833In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21835In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21836In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21837Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-21838In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-21839In the Linux kernel, the following vulnerability has been re…5.5
- CVE-2025-2184A credential management flaw in Palo Alto Networks Cortex XD…5.3
Are you affected by CVE-2025-21834?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
