CVE-2025-21863

NameCVE-2025-21863
DescriptionIn the Linux kernel, the following vulnerability has been resolved: io_uring: prevent opcode speculation sqe->opcode is used for different tables, make sure we santitise it against speculations.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4664-1, DLA-4665-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)bullseye5.10.223-1vulnerable
bullseye (security)5.10.259-1fixed
bookworm6.1.170-3vulnerable
bookworm (security)6.1.176-1fixed
trixie6.12.86-1fixed
trixie (security)6.12.94-1fixed
forky7.0.13-1fixed
sid7.1.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcebullseye5.10.259-1DLA-4664-1
linuxsourcebookworm6.1.176-1DLA-4665-1
linuxsource(unstable)6.12.17-1

Notes

https://git.kernel.org/linus/1e988c3fe1264708f4f92109203ac5b1d65de50b (6.14-rc4)

Search for package or bug name: Reporting problems