CVE-2025-21682

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 31, 2025
Updated: Feb 4, 2025
CWE ID 476

Summary

CVE-2025-21682 is a vulnerability affecting the Linux kernel's BNXT network driver. The issue arises due to a null-dereference caused by improper handling of XDP and Hardware Receive-Side Scaling (HW-GRO) reconfiguration. Before XDP is turned off, HW-GRO is disabled and does not get automatically re-enabled, leading to unpredictable behavior. A change in the number of Rx rings can result in conflicting reconfiguration commands, causing the driver to access a freed ring and crash. This vulnerability has been present since the addition of XDP support but became more significant with the commit 98ba1d931f61.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share