cbcvebase.
CVE-2025-21848
published 2025-03-12

CVE-2025-21848: In the Linux kernel, the following vulnerability has been resolved: nfp: bpf: Add check for nfp_app_ctrl_msg_alloc() Add check for the return value of…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
14.0th percentile
In the Linux kernel, the following vulnerability has been resolved: nfp: bpf: Add check for nfp_app_ctrl_msg_alloc() Add check for the return value of nfp_app_ctrl_msg_alloc() in nfp_bpf_cmsg_alloc() to prevent null pointer dereference.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= ff3d43f7568c82b335d7df2d40a31447c3fce10c < d64c6ca420019712e194fe095b55f87363e22a9ad64c6ca420019712e194fe095b55f87363e22a9a
linuxlinux>= ff3d43f7568c82b335d7df2d40a31447c3fce10c < e976ea6c5e1b005c64467cbf94a8577aae9c7d81e976ea6c5e1b005c64467cbf94a8577aae9c7d81
linuxlinux>= ff3d43f7568c82b335d7df2d40a31447c3fce10c < 924b239f9704566e0d86abd894d2d64bd73c11eb924b239f9704566e0d86abd894d2d64bd73c11eb
linuxlinux>= ff3d43f7568c82b335d7df2d40a31447c3fce10c < 1358d8e07afdf21d49ca6f00c56048442977e00a1358d8e07afdf21d49ca6f00c56048442977e00a
linuxlinux>= ff3d43f7568c82b335d7df2d40a31447c3fce10c < 29ccb1e4040da6ff02b7e64efaa2f8e6bf06020d29ccb1e4040da6ff02b7e64efaa2f8e6bf06020d
linuxlinux>= ff3d43f7568c82b335d7df2d40a31447c3fce10c < 897c32cd763fd11d0b6ed024c52f44d2475bb820897c32cd763fd11d0b6ed024c52f44d2475bb820
linuxlinux>= ff3d43f7568c82b335d7df2d40a31447c3fce10c < bd97f60750bb581f07051f98e31dfda59d3a783bbd97f60750bb581f07051f98e31dfda59d3a783b
linuxlinux>= ff3d43f7568c82b335d7df2d40a31447c3fce10c < 878e7b11736e062514e58f3b445ff343e6705537878e7b11736e062514e58f3b445ff343e6705537
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.17-16.12.17-1
linuxlinux_kernel>= 0 < 6.12.17-16.12.17-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-78.786.8.0-78.78
linuxlinux_kernel>= 4.16 < 6.1.1306.1.130
linuxlinux_kernel>= 6.13 < 6.13.56.13.5
linuxlinux_kernel>= 6.2 < 6.6.806.6.80
linuxlinux_kernel>= 6.7 < 6.12.176.12.17
msrcazl3_kernel_6.6.78.1-3_on_azure_linux_3.0
msrcazl3_kernel_6.6.82.1-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.