CVE-2025-21751

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 27, 2025
CWE ID 416

Summary

CVE-2025-21751 is a vulnerability affecting the Linux kernel. During matcher disconnect, if firmware failure occurs, the error flow reconnects the matcher and returns an error, continuing the execution of the calling function and eventually freeing the matcher being disconnected. This results in a use-after-free condition leading to a crash. The patch resolves this issue by preventing the reconnection of the matcher when a FW command fails during disconnect. Although this error handling may result in bad steering state and resource leakage, the primary goal is to avoid crashing the machine with a use-after-free error.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share