CVE-2025-21702NULL Pointer Dereference in Linux

Severity
7.0HIGHNVD
OSV8.8OSV7.8OSV7.1OSV5.5
EPSS
0.0%
top 90.69%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 18
Latest updateNov 21

Description

In the Linux kernel, the following vulnerability has been resolved: pfifo_tail_enqueue: Drop new packet when sch->limit == 0 Expected behaviour: In case we reach scheduler's limit, pfifo_tail_enqueue() will drop a packet in scheduler's queue and decrease scheduler's qlen by one. Then, pfifo_tail_enqueue() enqueue new packet and increase scheduler's qlen by one. Finally, pfifo_tail_enqueue() return `NET_XMIT_CN` status code. Weird behaviour: In case we set `sch->limit == 0` and trigger pfifo_t

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages8 packages

NVDlinux/linux_kernel2.6.345.4.291+7
Debianlinux/linux_kernel< 5.10.237-1+3
Ubuntulinux/linux_kernel< 5.4.0-214.234+4
CVEListV5linux/linux57dbb2d83d100ea601c54fe129bfde0678db5dee78285b53266d6d51fa4ff504a23df03852eba84e+8
debiandebian/linux< linux 6.1.133-1 (bookworm)

Patches

🔴Vulnerability Details

34
OSV
linux-raspi-5.4 vulnerabilities2025-05-28
OSV
linux-raspi vulnerabilities2025-05-28
OSV
linux-raspi vulnerabilities2025-05-26
OSV
linux-raspi-realtime vulnerabilities2025-05-20
OSV
linux-xilinx-zynqmp vulnerabilities2025-05-02

📋Vendor Advisories

38
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2025-132232025-11-21
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2025-217022025-10-10
CISA ICS
Siemens SIMATIC S7-1500 CPU Family2025-06-12
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2025-05-28
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2025-05-28