[LTS 8.6] CVE-2025-21786 #408
Draft
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
[LTS 8.6]
CVE-2025-21786
VULN-54090
Problem
https://access.redhat.com/security/cve/CVE-2025-21786
Applicability: no
The CVE-2025-21786 does not apply to LTS 8.6. The argument follows the same logic as laid out in #406.
The history of the affected file
kernel/workqueue.c
inciqlts8_6
is visibly different from that ofciqlts9_4
, although fully contained within, with 73 commits missing.However, the key commits related to the problem have the same status (either missing or present):
kernel/workqueue.c
's history. The code waiting for the rescuer (and removal of which caused the bug) is present inciqlts8_6
's revision ofkernel/workqueue.c
just as it is inciqlts9_4
:kernel-src-tree/kernel/workqueue.c
Lines 3559 to 3560 in 83208b0
put_pwq(…)
where it is, are present.Additionaly, the "Using the patched version is not without any cost" argument as well as "RedHat's "Affected" classification doesn't hold much weight" apply to the LTS 8.6 version with no changes.