CVE-2025-21676

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 31, 2025
Updated: Feb 4, 2025
CWE ID 476

Summary

CVE-2025-21676 is a vulnerability affecting the Linux kernel's FEC driver. The fec_enet_update_cbd function calls page_pool_dev_alloc_pages but fails to handle the error when it returns a NULL pointer. This error, while rare, can occur under memory pressure, particularly when writing to a SATA HDD attached to an imx6q. The driver continues to use the NULL pointer, leading to a crash. This issue has been resolved by the commit that drops the current packet when encountering the memory allocation error.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share