CVE-2025-21901
published 2025-04-01CVE-2025-21901: In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add sanity checks on rdev validity There is a possibility that ulp_irq_stop…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.2th percentile
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Add sanity checks on rdev validity
There is a possibility that ulp_irq_stop and ulp_irq_start
callbacks will be called when the device is in detached state.
This can cause a crash due to NULL pointer dereference as
the rdev is already freed.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.12.19-1 (forky) | linux 6.12.19-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= cc5b9b48d44756a87170f3901c6c2fd99e6b89b2 < aed1bc673907e3df372b317c10ff2f3582f8bf1a | aed1bc673907e3df372b317c10ff2f3582f8bf1a |
| linux | linux | >= cc5b9b48d44756a87170f3901c6c2fd99e6b89b2 < 8cb0eef46d70a99c88c26a1addb7fd955242e0e6 | 8cb0eef46d70a99c88c26a1addb7fd955242e0e6 |
| linux | linux | >= cc5b9b48d44756a87170f3901c6c2fd99e6b89b2 < f0df225d12fcb049429fb5bf5122afe143c2dd15 | f0df225d12fcb049429fb5bf5122afe143c2dd15 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.12.19-1 | 6.12.19-1 |
| linux | linux_kernel | >= 0 < 6.12.19-1 | 6.12.19-1 |
| linux | linux_kernel | >= 6.12 < 6.12.18 | 6.12.18 |
| linux | linux_kernel | >= 6.13 < 6.13.6 | 6.13.6 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.12.17/6.13.5 bnxt_re null pointer dereference (WID-SEC-2025-0683)
vuldb·2026-07-30·CVSS 5.5
CVE-2025-21901 [MEDIUM] Linux Kernel up to 6.12.17/6.13.5 bnxt_re null pointer dereference (WID-SEC-2025-0683)
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.12.17/6.13.5. Affected by this vulnerability is an unknown functionality of the component bnxt_re. Executing a manipulation can lead to null pointer dereference.
This vulnerability is tracked as CVE-2025-21901. The attack is only possible within the local network. No exploit exists.
It is advisable to upgrade the affected component.
GHSA
GHSA-j57r-qmgx-xp34: In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Add sanity checks on rdev validity
There is a possibility that ulp
ghsa_unreviewed·2025-04-01
CVE-2025-21901 [MEDIUM] CWE-476 GHSA-j57r-qmgx-xp34: In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Add sanity checks on rdev validity
There is a possibility that ulp
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Add sanity checks on rdev validity
There is a possibility that ulp_irq_stop and ulp_irq_start
callbacks will be called when the device is in detached state.
This can cause a crash due to NULL pointer dereference as
the rdev is already freed.
OSV
CVE-2025-21901: In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add sanity checks on rdev validity There is a possibility that ulp_i
osv·2025-04-01·CVSS 5.5
CVE-2025-21901 [MEDIUM] CVE-2025-21901: In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add sanity checks on rdev validity There is a possibility that ulp_i
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add sanity checks on rdev validity There is a possibility that ulp_irq_stop and ulp_irq_start callbacks will be called when the device is in detached state. This can cause a crash due to NULL pointer dereference as the rdev is already freed.
Red Hat
kernel: RDMA/bnxt_re: Add sanity checks on rdev validity
vendor_redhat·2025-04-01·CVSS 5.5
CVE-2025-21901 [MEDIUM] CWE-476 kernel: RDMA/bnxt_re: Add sanity checks on rdev validity
kernel: RDMA/bnxt_re: Add sanity checks on rdev validity
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Add sanity checks on rdev validity
There is a possibility that ulp_irq_stop and ulp_irq_start
callbacks will be called when the device is in detached state.
This can cause a crash due to NULL pointer dereference as
the rdev is already freed.
Package: kernel (Red Hat Enterprise Linux 10) - Fix deferred
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not affected
Package: kernel (Red Hat Ent
Debian
CVE-2025-21901: linux - In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_r...
vendor_debian·2025·CVSS 5.5
CVE-2025-21901 [MEDIUM] CVE-2025-21901: linux - In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_r...
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add sanity checks on rdev validity There is a possibility that ulp_irq_stop and ulp_irq_start callbacks will be called when the device is in detached state. This can cause a crash due to NULL pointer dereference as the rdev is already freed.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.12.19-1)
sid: resolved (fixed in 6.12.19-1)
trixie: resolved (fixed in 6.12.19-1)
No detection rules found.
No public exploits indexed.
2025-04-01
Published