Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-21901— RDMA/bnxt_re: Add sanity checks on rdev validity

CVSS 7.8 · High EPSS 0.20% · P10

Possible ATT&CK Techniques 1AI

T1211 · Exploitation for Stealth

Affected Version Matrix 8

VendorProductVersion RangeStatus
LinuxLinuxcc5b9b48d44756a87170f3901c6c2fd99e6b89b2< aed1bc673907e3df372b317c10ff2f3582f8bf1aaffected
cc5b9b48d44756a87170f3901c6c2fd99e6b89b2< 8cb0eef46d70a99c88c26a1addb7fd955242e0e6affected
cc5b9b48d44756a87170f3901c6c2fd99e6b89b2< f0df225d12fcb049429fb5bf5122afe143c2dd15affected
6.12affected
< 6.12unaffected
6.12.18≤ 6.12.*unaffected
6.13.6≤ 6.13.*unaffected
6.14≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-21901

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RDMA/bnxt_re: Add sanity checks on rdev validity
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add sanity checks on rdev validity There is a possibility that ulp_irq_stop and ulp_irq_start callbacks will be called when the device is in detached state. This can cause a crash due to NULL pointer dereference as the rdev is already freed.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于bnxt_re中缺少对rdev有效性的健全性检查。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux cc5b9b48d44756a87170f3901c6c2fd99e6b89b2 ~ aed1bc673907e3df372b317c10ff2f3582f8bf1a -
LinuxLinux 6.12 -

II. Public POCs for CVE-2025-21901

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-21901

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-04-01 · 93 CVEs total

CVE-2025-219279.8 CRITICALnvme-tcp: fix potential memory corruption in nvme_tcp_recv_pdu()
CVE-2025-219549.8 CRITICALnetmem: prevent TX of unreadable skbs
CVE-2025-219698.8 HIGHBluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd
CVE-2025-219558.8 HIGHksmbd: prevent connection release during oplock break notification
CVE-2025-219728.8 HIGHnet: mctp: unshare packets when reassembling
CVE-2025-219468.8 HIGHksmbd: fix out-of-bounds in parse_sec_desc()
CVE-2025-219458.8 HIGHksmbd: fix use-after-free in smb2_lock
CVE-2025-219678.8 HIGHksmbd: fix use-after-free in ksmbd_free_work_struct
CVE-2025-219478.1 HIGHksmbd: fix type confusion via race condition when using ipc_msg_send_request
CVE-2025-219237.8 HIGHHID: hid-steam: Fix use-after-free when detaching device
CVE-2025-219347.8 HIGHrapidio: fix an API misues when rio_add_net() fails
CVE-2025-219497.8 HIGHLoongArch: Set hugetlb mmap base address aligned with pmd size
CVE-2025-219397.8 HIGHdrm/xe/hmm: Don't dereference struct page pointers without notifier lock
CVE-2025-219147.8 HIGHslimbus: messaging: Free transaction ID in delayed interrupt scenario
CVE-2025-219247.8 HIGHnet: hns3: make sure ptp clock is unregister and freed if hclge_ptp_get_cycle returns an e
CVE-2025-219587.8 HIGHRevert "openvswitch: switch to per-action label counting in conntrack"
CVE-2025-219657.8 HIGHsched_ext: Validate prev_cpu in scx_bpf_select_cpu_dfl()
CVE-2025-219267.8 HIGHnet: gso: fix ownership in __udp_gso_segment
CVE-2025-219197.8 HIGHsched/fair: Fix potential memory corruption in child_cfs_rq_on_list
CVE-2025-219857.8 HIGHdrm/amd/display: Fix out-of-bound accesses

Showing top 20 of 93 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-21901

No comments yet


Leave a comment