CVE-2025-21917

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 1, 2025
Updated: Apr 11, 2025
CWE ID 476

Summary

CVE-2025-21917 is a vulnerability affecting the Linux kernel on Renesas RZ/G2L SoCs. During continuous unbind/bind operations on USB drivers available on these devices, a kernel crash can occur due to a NULL pointer dereference in the usbhsc_notify_hotplug() function. This issue arises when the delayed work associated with the function is not properly flushed, leading to its execution when driver resources are unavailable. The vulnerability has been resolved by flushing the delayed work to prevent its execution in such instances.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share