cbcvebase.
CVE-2025-21744
published 2025-02-27

CVE-2025-21744: In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix NULL pointer dereference in brcmf_txfinalize() On removal of the device…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.22%
13.3th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: fix NULL pointer dereference in brcmf_txfinalize() On removal of the device or unloading of the kernel module a potential NULL pointer dereference occurs. The following sequence deletes the interface: brcmf_detach() brcmf_remove_interface() brcmf_del_if() Inside the brcmf_del_if() function the drvr->if2bss[ifidx] is updated to BRCMF_BSSIDX_INVALID (-1) if the bsscfgidx matches. After brcmf_remove_interface() call the brcmf_proto_detach() function is called providing the following sequence: brcmf_detach() brcmf_proto_detach() brcmf_proto_msgbuf_detach() brcmf_flowring_detach() brcmf_msgbuf_delete_flowring() brcmf_msgbuf_remove_flowring() brcmf_flowring_delete() brcmf_get_ifp() brcmf_txfinalize() Since brcmf_get_ip() can and actually will return NULL in this case the call to brcmf_txfinalize() will result in a NULL pointer dereference inside brcmf_txfinalize() when trying to update ifp->ndev->stats.tx_errors. This will only happen if a flowring still has an skb. Although the NULL pointer dereference has only been seen when trying to update the tx statistic, all other uses of the ifp pointer have been guarded as well with an early return if ifp is NULL.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 4.7.10 < 4.84.8
linuxlinux>= 4.8.4 < 4.94.9
linuxlinux>= 7f00ee2bbc630900ba16fc2690473f3e2db0e264 < 2326e19190e176fd72bb542b837a9d2b7fcb86932326e19190e176fd72bb542b837a9d2b7fcb8693
linuxlinux>= 7f00ee2bbc630900ba16fc2690473f3e2db0e264 < 59ff4fa653ff6db07c61152516ffba79c2a74bda59ff4fa653ff6db07c61152516ffba79c2a74bda
linuxlinux>= 7f00ee2bbc630900ba16fc2690473f3e2db0e264 < 61541d9b5a23df33934fcc620a3a81f246b1b24061541d9b5a23df33934fcc620a3a81f246b1b240
linuxlinux>= 7f00ee2bbc630900ba16fc2690473f3e2db0e264 < 4e51d6d093e763348916e69d06d87e0a5593661b4e51d6d093e763348916e69d06d87e0a5593661b
linuxlinux>= 7f00ee2bbc630900ba16fc2690473f3e2db0e264 < 3877fc67bd3d5566cc12763bce39710ceb74a97d3877fc67bd3d5566cc12763bce39710ceb74a97d
linuxlinux>= 7f00ee2bbc630900ba16fc2690473f3e2db0e264 < fbbfef2a5b858eab55741a58b2ac9a0cc8d53c58fbbfef2a5b858eab55741a58b2ac9a0cc8d53c58
linuxlinux>= 7f00ee2bbc630900ba16fc2690473f3e2db0e264 < a2beefc4fa49ebc22e664dc6b39dbd054f8488f9a2beefc4fa49ebc22e664dc6b39dbd054f8488f9
linuxlinux>= 7f00ee2bbc630900ba16fc2690473f3e2db0e264 < 68abd0c4ebf24cd499841a488b97a6873d5efabb68abd0c4ebf24cd499841a488b97a6873d5efabb
linuxlinux_kernel< 6.1.1296.1.129
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 6.12.15-16.12.15-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67
linuxlinux_kernel>= 6.13 < 6.13.36.13.3
linuxlinux_kernel>= 6.2 < 6.6.786.6.78

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.