CVE-2025-21981

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 1, 2025
Updated: Apr 10, 2025
CWE ID 401

Summary

CVE-2025-21981 involves a memory leak in the Linux kernel's accelerated Receive Flow Steering (aRFS) module. During VSI (Virtual Switch Interface) reconfiguration executed during reset, memory allocation occurs without prior release of already allocated resources, leading to a memory leak. The memory leak is detected with the signature "[unreferenced object ...]", and the backtrace includes the functions ice_init_arfs, ice_vsi_cfg_def, and ice_vsi_setup from the ice driver. This vulnerability can potentially be exploited for denial of service attacks by exhausting system memory.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share