cbcvebase.
CVE-2025-21855
published 2025-03-12

CVE-2025-21855: In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Don't reference skb after sending to VIOS Previously, after successfully flushing…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
11.6th percentile
In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Don't reference skb after sending to VIOS Previously, after successfully flushing the xmit buffer to VIOS, the tx_bytes stat was incremented by the length of the skb. It is invalid to access the skb memory after sending the buffer to the VIOS because, at any point after sending, the VIOS can trigger an interrupt to free this memory. A race between reading skb->len and freeing the skb is possible (especially during LPM) and will result in use-after-free: BUG: KASAN: slab-use-after-free in ibmvnic_xmit+0x75c/0x1808 [ibmvnic] Read of size 4 at addr c00000024eb48a70 by task hxecom/14495 Call Trace: [c000000118f66cf0] [c0000000018cba6c] dump_stack_lvl+0x84/0xe8 (unreliable) [c000000118f66d20] [c0000000006f0080] print_report+0x1a8/0x7f0 [c000000118f66df0] [c0000000006f08f0] kasan_report+0x128/0x1f8 [c000000118f66f00] [c0000000006f2868] __asan_load4+0xac/0xe0 [c000000118f66f20] [c0080000046eac84] ibmvnic_xmit+0x75c/0x1808 [ibmvnic] [c000000118f67340] [c0000000014be168] dev_hard_start_xmit+0x150/0x358 Freed by task 0: kasan_save_stack+0x34/0x68 kasan_save_track+0x2c/0x50 kasan_save_free_info+0x64/0x108 __kasan_mempool_poison_object+0x148/0x2d4 napi_skb_cache_put+0x5c/0x194 net_tx_action+0x154/0x5b8 handle_softirqs+0x20c/0x60c do_softirq_own_stack+0x6c/0x88 The buggy address belongs to the object at c00000024eb48a00 which belongs to the cache skbuff_head_cache of size 224

Affected

23 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= 032c5e82847a2214c3196a90f0aeba0ce252de58 < 501ac6a7e21b82e05207c6b4449812d82820f306501ac6a7e21b82e05207c6b4449812d82820f306
linuxlinux>= 032c5e82847a2214c3196a90f0aeba0ce252de58 < 093b0e5c90592773863f300b908b741622eef597093b0e5c90592773863f300b908b741622eef597
linuxlinux>= 032c5e82847a2214c3196a90f0aeba0ce252de58 < 25dddd01dcc8ef3acff964dbb32eeb0d89f098e925dddd01dcc8ef3acff964dbb32eeb0d89f098e9
linuxlinux>= 032c5e82847a2214c3196a90f0aeba0ce252de58 < abaff2717470e4b5b7c0c3a90e128b211a23da09abaff2717470e4b5b7c0c3a90e128b211a23da09
linuxlinux>= 032c5e82847a2214c3196a90f0aeba0ce252de58 < bdf5d13aa05ec314d4385b31ac974d6c7e0997c9bdf5d13aa05ec314d4385b31ac974d6c7e0997c9
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.17-16.12.17-1
linuxlinux_kernel>= 0 < 6.12.17-16.12.17-1
linuxlinux_kernel>= 0 < 5.15.0-164.1745.15.0-164.174
linuxlinux_kernel>= 0 < 6.8.0-78.786.8.0-78.78
linuxlinux_kernel>= 0 < 4.4.0-276.3104.4.0-276.310
linuxlinux_kernel>= 0 < 4.15.0-245.2574.15.0-245.257
linuxlinux_kernel>= 0 < 5.4.0-224.2445.4.0-224.244
linuxlinux_kernel>= 4.5 < 6.1.1306.1.130
linuxlinux_kernel>= 6.13 < 6.13.56.13.5
linuxlinux_kernel>= 6.2 < 6.6.806.6.80
linuxlinux_kernel>= 6.7 < 6.12.176.12.17
msrcazl3_kernel_6.6.78.1-3_on_azure_linux_3.0
msrccbl2_kernel_5.15.182.1-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.