CVE-2025-21715

Local privilege escalation via freed dm dereference

Published Feb 27, 2025 · Updated May 23, 2026

Use-after-free in the Linux kernel dm9000 driver allows local users to escalate privileges when the network device is removed. In dm9000_drv_remove(), free_netdev() releases the netdev-private dm object before later cleanup code dereferences dm to release platform resources. Exploitation requires local low-privileged access and a system using the Davicom DM9000 driver; successful memory corruption grants kernel-level control.

CVSS severity7.8
High
EPSS probability0.24%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Use-after-free in the Linux kernel dm9000 driver allows local users to escalate privileges when the network device is removed. In dm9000_drv_remove(), free_netdev() releases the netdev-private dm object before later cleanup code dereferences dm to release platform resources. Exploitation requires local low-privileged access and a system using the Davicom DM9000 driver; successful memory corruption grants kernel-level control.

The record

CVE
CVE-2025-21715
Published
Feb 27, 2025
Updated
May 23, 2026
Vendor
The Linux Kernel Organization
Product
Linux
Classifications
CWE-416, T1068
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. Feb 27, 2025CVE publishedPublication date reported by the CVE source.
  2. May 23, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=4.14.226 <4.15
  2. Affected versionversion=4.19.181 <4.20
  3. Affected versionversion=427b3fc3d5244fef9c1f910a9c699f2690642f83
  4. Affected versionversion=4.4.262 <4.5
  5. Affected versionversion=4.9.262 <4.10
  6. Affected versionversion=4fd0654b8f2129b68203974ddee15f804ec011c2 <a53cb72043443ac787ec0b5fa17bb3f8ff3d462b
  7. Affected versionversion=5.10.24 <5.10.235
  8. Affected versionversion=5.11.7 <5.12
  9. Affected versionversion=5.12
  10. Affected versionversion=5.4.106 <5.4.291
  11. Affected versionversion=9808f032c4d971cbf2b01411a0a2a8ee0040efe3
  12. Affected versionversion=9c49181c201d434186ca6b1a7b52e29f4169f6f8
  13. Affected versionversion=a1f308089257616cdb91b4334c5eaa81ae17e387
  14. Affected versionversion=cf9e60aa69ae6c40d3e3e4c94dd6c8de31674e9b <19e65c45a1507a1a2926649d2db3583ed9d55fd9
  15. Affected versionversion=cf9e60aa69ae6c40d3e3e4c94dd6c8de31674e9b <2013c95df6752d9c88221d0f0f37b6f197969390
  16. Affected versionversion=cf9e60aa69ae6c40d3e3e4c94dd6c8de31674e9b <5a54367a7c2378c65aaa4d3cfd952f26adef7aa7
  17. Affected versionversion=cf9e60aa69ae6c40d3e3e4c94dd6c8de31674e9b <7d7d201eb3b766abe590ac0dda7a508b7db3e357
  18. Affected versionversion=cf9e60aa69ae6c40d3e3e4c94dd6c8de31674e9b <c411f9a5fdc9158e8f7c57eac961d3df3eb4d8ca
  19. Affected versionversion=cf9e60aa69ae6c40d3e3e4c94dd6c8de31674e9b <c94ab07edc2843e2f3d46dbd82e5c681503aaadf
  20. Affected versionversion=d182994b2b6e23778b146a230efac8f1d77a3445
  21. Affected versionversion=d28e783c20033b90a64d4e1307bafb56085d8184 <db79e982c5f9e39ab710cbce55b05f2f5e6f1ca9

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

The Linux Kernel Organization · Linuxversion=4.14.226 <4.15; version=4.19.181 <4.20; version=427b3fc3d5244fef9c1f910a9c699f2690642f83; version=4.4.262 <4.5; version=4.9.262 <4.10; version=4fd0654b8f2129b68203974ddee15f804ec011c2 <a53cb72043443ac787ec0b5fa17bb3f8ff3d462b; version=5.10.24 <5.10.235; version=5.11.7 <5.12; version=5.12; version=5.4.106 <5.4.291; version=9808f032c4d971cbf2b01411a0a2a8ee0040efe3; version=9c49181c201d434186ca6b1a7b52e29f4169f6f8; version=a1f308089257616cdb91b4334c5eaa81ae17e387; version=cf9e60aa69ae6c40d3e3e4c94dd6c8de31674e9b <19e65c45a1507a1a2926649d2db3583ed9d55fd9; version=cf9e60aa69ae6c40d3e3e4c94dd6c8de31674e9b <2013c95df6752d9c88221d0f0f37b6f197969390; version=cf9e60aa69ae6c40d3e3e4c94dd6c8de31674e9b <5a54367a7c2378c65aaa4d3cfd952f26adef7aa7; version=cf9e60aa69ae6c40d3e3e4c94dd6c8de31674e9b <7d7d201eb3b766abe590ac0dda7a508b7db3e357; version=cf9e60aa69ae6c40d3e3e4c94dd6c8de31674e9b <c411f9a5fdc9158e8f7c57eac961d3df3eb4d8ca; version=cf9e60aa69ae6c40d3e3e4c94dd6c8de31674e9b <c94ab07edc2843e2f3d46dbd82e5c681503aaadf; version=d182994b2b6e23778b146a230efac8f1d77a3445; version=d28e783c20033b90a64d4e1307bafb56085d8184 <db79e982c5f9e39ab710cbce55b05f2f5e6f1ca9

Published CVSS scores

7.8CISA-ADPCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-416Use After Free
T1068Exploitation for Privilege Escalation

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo