cbcvebase.
CVE-2025-21656
published 2025-01-21

CVE-2025-21656: In the Linux kernel, the following vulnerability has been resolved: hwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
9.9th percentile
In the Linux kernel, the following vulnerability has been resolved: hwmon: (drivetemp) Fix driver producing garbage data when SCSI errors occur scsi_execute_cmd() function can return both negative (linux codes) and positive (scsi_cmnd result field) error codes. Currently the driver just passes error codes of scsi_execute_cmd() to hwmon core, which is incorrect because hwmon only checks for negative error codes. This leads to hwmon reporting uninitialized data to userspace in case of SCSI errors (for example if the disk drive was disconnected). This patch checks scsi_execute_cmd() output and returns -EIO if it's error code is positive. [groeck: Avoid inline variable declaration for portability]

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.10-1 (forky)linux 6.12.10-1 (forky)
linuxlinux
linuxlinux>= 5b46903d8bf372e563bf2150d46b87fff197a109 < 53e25b10a28edaf8c2a1d3916fd8929501a50dfc53e25b10a28edaf8c2a1d3916fd8929501a50dfc
linuxlinux>= 5b46903d8bf372e563bf2150d46b87fff197a109 < 42268d885e44af875a6474f7bba519cc6cea6a9d42268d885e44af875a6474f7bba519cc6cea6a9d
linuxlinux>= 5b46903d8bf372e563bf2150d46b87fff197a109 < 82163d63ae7a4c36142cd252388737205bb7e4b982163d63ae7a4c36142cd252388737205bb7e4b9
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 6.12.10-16.12.10-1
linuxlinux_kernel>= 0 < 6.8.0-60.636.8.0-60.63
linuxlinux_kernel>= 5.6 < 6.6.726.6.72
linuxlinux_kernel>= 6.7 < 6.12.106.12.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.