cbcvebase.
CVE-2025-21802
published 2025-02-27

CVE-2025-21802: In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix oops when unload drivers paralleling When unload hclge driver, it tries to…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
9.9th percentile
In the Linux kernel, the following vulnerability has been resolved: net: hns3: fix oops when unload drivers paralleling When unload hclge driver, it tries to disable sriov first for each ae_dev node from hnae3_ae_dev_list. If user unloads hns3 driver at the time, because it removes all the ae_dev nodes, and it may cause oops. But we can't simply use hnae3_common_lock for this. Because in the process flow of pci_disable_sriov(), it will trigger the remove flow of VF, which will also take hnae3_common_lock. To fixes it, introduce a new mutex to protect the unload process.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 0dd8a25f355b4df2d41c08df1716340854c7d4c5 < 8c640dd3d900cc8988a39c007591f1deee776df48c640dd3d900cc8988a39c007591f1deee776df4
linuxlinux>= 0dd8a25f355b4df2d41c08df1716340854c7d4c5 < e876522659012ef2e73834a0b9f1cbe3f74d5fade876522659012ef2e73834a0b9f1cbe3f74d5fad
linuxlinux>= 0dd8a25f355b4df2d41c08df1716340854c7d4c5 < b5a8bc47aa0a4aa8bca5466dfa2d12dbb5b3cd0cb5a8bc47aa0a4aa8bca5466dfa2d12dbb5b3cd0c
linuxlinux>= 0dd8a25f355b4df2d41c08df1716340854c7d4c5 < 82736bb83fb0221319c85c2e9917d0189cd84e1e82736bb83fb0221319c85c2e9917d0189cd84e1e
linuxlinux>= 0dd8a25f355b4df2d41c08df1716340854c7d4c5 < cafe9a27e22736d4a01b3933e36225f9857c7988cafe9a27e22736d4a01b3933e36225f9857c7988
linuxlinux>= 0dd8a25f355b4df2d41c08df1716340854c7d4c5 < 92e5995773774a3e70257e9c95ea03518268bea592e5995773774a3e70257e9c95ea03518268bea5
linuxlinux>= 4.19.214 < 4.204.20
linuxlinux>= 5.10.76 < 5.10.2355.10.235
linuxlinux>= 5.14.15 < 5.155.15
linuxlinux>= 5.4.156 < 5.55.5
linuxlinux>= d36b15e3e7b5937cb1f6ac590a85facc3a320642 < 622d92a67656e5c4d2d6ccac02d688ed995418c6622d92a67656e5c4d2d6ccac02d688ed995418c6
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 6.12.13-16.12.13-1
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-64.676.8.0-64.67

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.