cbcvebase.
CVE-2025-21735
published 2025-02-27

CVE-2025-21735: In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Add bounds checking in nci_hci_create_pipe() The "pipe" variable is a u8 which…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
26.3th percentile
In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Add bounds checking in nci_hci_create_pipe() The "pipe" variable is a u8 which comes from the network. If it's more than 127, then it results in memory corruption in the caller, nci_hci_connect_gate().

Affected

29 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux>= a1b0b9415817c14d207921582f269d03f848b69f < bd249109d266f1d52548c46634a15b71656e0d44bd249109d266f1d52548c46634a15b71656e0d44
linuxlinux>= a1b0b9415817c14d207921582f269d03f848b69f < 674e17c5933779a8bf5c15d596fdfcb5ccdebbc2674e17c5933779a8bf5c15d596fdfcb5ccdebbc2
linuxlinux>= a1b0b9415817c14d207921582f269d03f848b69f < 10b3f947b609713e04022101f492d288a014ddfa10b3f947b609713e04022101f492d288a014ddfa
linuxlinux>= a1b0b9415817c14d207921582f269d03f848b69f < d5a461c315e5ff92657f84d8ba50caa5abf5c22ad5a461c315e5ff92657f84d8ba50caa5abf5c22a
linuxlinux>= a1b0b9415817c14d207921582f269d03f848b69f < 172cdfc3a5ea20289c58fb73dadc6fd4a8784a4e172cdfc3a5ea20289c58fb73dadc6fd4a8784a4e
linuxlinux>= a1b0b9415817c14d207921582f269d03f848b69f < 2ae4bade5a64d126bd18eb66bd419005c55502182ae4bade5a64d126bd18eb66bd419005c5550218
linuxlinux>= a1b0b9415817c14d207921582f269d03f848b69f < 59c7ed20217c0939862fbf8145bc49d5b3a13f4f59c7ed20217c0939862fbf8145bc49d5b3a13f4f
linuxlinux>= a1b0b9415817c14d207921582f269d03f848b69f < 110b43ef05342d5a11284cc8b21582b698b4ef1c110b43ef05342d5a11284cc8b21582b698b4ef1c
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67
linuxlinux_kernel>= 0 < 4.4.0-279.3134.4.0-279.313
linuxlinux_kernel>= 0 < 4.15.0-248.2604.15.0-248.260
linuxlinux_kernel>= 4.4 < 6.1.1296.1.129
linuxlinux_kernel>= 6.13 < 6.13.36.13.3
linuxlinux_kernel>= 6.2 < 6.6.786.6.78
linuxlinux_kernel>= 6.7 < 6.12.146.12.14
msrcazl3_kernel_6.6.64.2-9_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.