CVE-2025-21726 is a use-after-free vulnerability in the Linux kernel padata subsystem's asynchronous reorder_work processing. During concurrent cryptographic request processing, padata_reorder can queue reorder work after a new request is added through padata_do_serial. If padata_serial_worker completes the outstanding request and crypto_del_alg frees the associated parallel-data object (pd) before the queued work executes, invoke_padata_reorder accesses the freed object. An earlier fix for the _do_serial path did not protect this queued-work lifetime. The correction retains a reference to pd throughout the lifetime of the queued reorder work.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A use-after-free vulnerability in the Linux kernel's padata subsystem. A race involving request reordering and algorithm deletion can free the parallel-data structure before queued reorder_work executes. The fix retains a reference until the queued work finishes. The affected Google COS kernel packages receive a high-severity rating, with a CVSS v3 base score of 7.8. The plugin recommends updating sys-kernel/lakitu-kernel-6_1 and related packages to version 18613.164.98 or later.
Use-after-free involving Linux kernel padata reorder work.
A high-severity Linux kernel use-after-free vulnerability in the padata subsystem's reorder_work handling. A race involving padata request processing and crypto algorithm deletion can free the pd object before invoke_padata_reorder accesses it, potentially causing use-after-free conditions.
A high-severity local use-after-free vulnerability in the Linux kernel padata subsystem's reorder_work handling. A race involving queued serial work and crypto algorithm deletion can leave reorder_work accessing a freed padata object.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.