cbcvebase.
CVE-2025-21682
published 2025-01-31

CVE-2025-21682: In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: always recalculate features after XDP clearing, fix null-deref Recalculate…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
12.1th percentile
In the Linux kernel, the following vulnerability has been resolved:

eth: bnxt: always recalculate features after XDP clearing, fix null-deref

Recalculate features when XDP is detached.

Before:
# ip li set dev eth0 xdp obj xdp_dummy.bpf.o sec xdp
# ip li set dev eth0 xdp off
# ethtool -k eth0 | grep gro
rx-gro-hw: off [requested on]

After:
# ip li set dev eth0 xdp obj xdp_dummy.bpf.o sec xdp
# ip li set dev eth0 xdp off
# ethtool -k eth0 | grep gro
rx-gro-hw: on

The fact that HW-GRO doesn't get re-enabled automatically is just
a minor annoyance. The real issue is that the features will randomly
come back during another reconfiguration which just happens to invoke
netdev_update_features(). The driver doesn't handle reconfiguring
two things at a time very robustly.

Starting with commit 98ba1d931f61 ("bnxt_en: Fix RSS logic in
__bnxt_reserve_rings()") we only reconfigure the RSS hash table
if the "effective" number of Rx rings has changed. If HW-GRO is
enabled "effective" number of rings is 2x what user sees.
So if we are in the bad state, with HW-GRO re-enablement "pending"
after XDP off, and we lower the rings by / 2 - the HW-GRO rings
doing 2x and the ethtool -L doing / 2 may cancel each other out,
and the:

if (old_rx_rings != bp->hw_resc.resv_rx_rings &&

condition in __bnxt_reserve_rings() will be false.
The RSS map won't get updated, and we'll crash with:

BUG: kernel NULL pointer dereference, address: 0000000000000168
RIP: 0010:__bnxt_hwrm_vnic_set_rss+0x13a/0x1a0
bnxt_hwrm_vnic_rss_cfg_p5+0x47/0x180
__bnxt_setup_vnic_p5+0x58/0x110
bnxt_init_nic+0xb72/0xf50
__bnxt_open_nic+0x40d/0xab0
bnxt_open_nic+0x2b/0x60
ethtool_set_channels+0x18c/0x1d0

As we try to access a freed ring.

The issue is present since XDP support was added, really, but
prior to commit 98ba1d931f61 ("bnxt_en: Fix RSS logic in
__bnxt_reserve_rings()") it wasn't causing major issues.

Affected

21 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.11-1 (forky)linux 6.12.11-1 (forky)
fig2dev_projectfig2dev>= 0 < 1:3.2.6a-6ubuntu1.1+esm11:3.2.6a-6ubuntu1.1+esm1
fig2dev_projectfig2dev>= 0 < 1:3.2.7a-7ubuntu0.1+esm11:3.2.7a-7ubuntu0.1+esm1
fig2dev_projectfig2dev>= 0 < 1:3.2.8b-1ubuntu0.1~esm11:3.2.8b-1ubuntu0.1~esm1
fig2dev_projectfig2dev>= 0 < 1:3.2.9-3ubuntu0.1~esm11:3.2.9-3ubuntu0.1~esm1
linuxlinux
linuxlinux>= 1054aee82321483dceabbb9b9e5d6512e8fe684b < 076a694a42ae3f0466bc6e4126050eeb7b7d299a076a694a42ae3f0466bc6e4126050eeb7b7d299a
linuxlinux>= 1054aee82321483dceabbb9b9e5d6512e8fe684b < 90336fc3d6f5e716ac39a9ddbbde453e23a5aa6590336fc3d6f5e716ac39a9ddbbde453e23a5aa65
linuxlinux>= 1054aee82321483dceabbb9b9e5d6512e8fe684b < 08831a894d18abfaabb5bbde7c2069a7fb41dd9308831a894d18abfaabb5bbde7c2069a7fb41dd93
linuxlinux>= 1054aee82321483dceabbb9b9e5d6512e8fe684b < f0aa6a37a3dbb40b272df5fc6db93c114688adcdf0aa6a37a3dbb40b272df5fc6db93c114688adcd
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.11-16.12.11-1
linuxlinux_kernel>= 0 < 6.12.11-16.12.11-1
linuxlinux_kernel>= 0 < 6.8.0-62.656.8.0-62.65
linuxlinux_kernel>= 4.16 < 6.12.116.12.11

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.