Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-21728

17
FAUCET Score

CVE-2025-21728 is a medium-severity vulnerability affecting the Linux kernel, specifically within BPF programs. The flaw arises when a BPF program executing in a non-preemptible context attempts to use the bpf_send_signal() kfunc, which can cause the system to sleep and lead to issues. With a CVSS score of 5.5, this local vulnerability (AV:L) has low attack complexity (AC:L) and requires low privileges (PR:L), potentially resulting in high availability impact (A:H) but no confidentiality or integrity impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.4.33, < 5.4.291CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.5.18, < 5.6CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.6.1, < 5.10.235CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.11, < 5.15.179CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 5.16, < 6.1.129CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.19%
Probability of exploitation in next 30 days
EPSS Percentile
8.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0019 is in the 44th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-0:5.14.0-611.5.1.el9_7
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (1)

redhatCVE-2025-21728Moderate

kernel: bpf: Send signals asynchronously if !preemptible

Feb 27, 2025

References

cert-portal.siemens.com / productcert/html/ssa-082556.html
cert-portal.siemens.com / productcert/html/ssa-265688.html
git.kernel.org / stable/c/092fc76b7ab4163e008f9cde596a58dad2108260
Patch
git.kernel.org / stable/c/78b97783496b454435639937db3303e900a24d3f
Patch
git.kernel.org / stable/c/87c544108b612512b254c8f79aa5c0a8546e2cc4
Patch
git.kernel.org / stable/c/be42a09fe898635b0093c0c8dac1bfabe225c240
Patch
git.kernel.org / stable/c/ce51eab2070e295d298f42a2f1db269cd1b56d55
Patch
git.kernel.org / stable/c/e306eaaa3d78b462db5f5b11e0171f9d2b6ca3f4
Patch
git.kernel.org / stable/c/eeef8e65041a031bd8a747a392c14b76a123a12c
Patch
git.kernel.org / stable/c/feba1308bc5e8e04cee751d39fae8a9b407a9034
Patch
lists.debian.org / debian-lts-announce/2025/03/msg00028.html
lists.debian.org / debian-lts-announce/2025/05/msg00030.html