CVE-2025-21671 is a use-after-free flaw in the Linux kernel's zram compressed-RAM driver. If zram_meta_alloc fails early, it frees zram->table without clearing the pointer; a local privileged user can then reset the failed, uninitialized zram device and cause zram_meta_free to access freed memory, potentially compromising system confidentiality, integrity, or availability. The issue is tracked as CWE-416 and is rated 6.7 (Moderate) by Red Hat, while NVD and CVE.org assign CVSS 7.8.
The flaw affects stable kernel lines beginning at 6.1.122, 6.6.68, and 6.12.7, and is fixed in 6.1.127, 6.6.74, and 6.12.11; administrators should deploy current stable kernel releases rather than cherry-picking the patch. Red Hat remediated supported RHEL 10 and RHEL 9 kernels through RHSA-2025:20095 and RHSA-2025:20518, respectively, while the RHEL 9 kernel-rt package remains affected; older unsupported kernel packages are outside Red Hat support scope.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2025:20095 for RHEL 10 and RHSA-2025:20518 for RHEL 9 to address CVE-2025-21671. Red Hat rated the local, privileged zram use-after-free vulnerability Moderate, with a CVSS v3.1 score of 6.7.
The Linux kernel CVE team announced CVE-2025-21671, a potential use-after-free in the zram driver caused by an early allocation-failure path leaving a freed zram table pointer non-NULL. The advisory identified fixes in Linux kernel versions 6.1.127, 6.6.74, and 6.12.11 and recommended upgrading to the latest stable release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.