CVE-2025-21917
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Apr 1, 2025
Updated: Apr 11, 2025
CWE ID 476
Summary
CVE-2025-21917 is a vulnerability affecting the Linux kernel on Renesas RZ/G2L SoCs. During continuous unbind/bind operations on USB drivers available on these devices, a kernel crash can occur due to a NULL pointer dereference in the usbhsc_notify_hotplug() function. This issue arises when the delayed work associated with the function is not properly flushed, leading to its execution when driver resources are unavailable. The vulnerability has been resolved by flushing the delayed work to prevent its execution in such instances.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.