CVE-2025-21848

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 12, 2025
Updated: Mar 13, 2025
CWE ID 476

Summary

CVE-2025-21848 is a vulnerability affecting the Linux kernel where a null pointer dereference can occur in the nfp_bpf_cmsg_alloc() function due to the lack of a check for the return value of nfp_app_ctrl_msg_alloc(). This issue has been resolved with the addition of a new check to prevent such occurrences, mitigating the potential risks associated with this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share