cbcvebase.
CVE-2025-21901
published 2025-04-01

CVE-2025-21901: In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add sanity checks on rdev validity There is a possibility that ulp_irq_stop…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.2th percentile
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add sanity checks on rdev validity There is a possibility that ulp_irq_stop and ulp_irq_start callbacks will be called when the device is in detached state. This can cause a crash due to NULL pointer dereference as the rdev is already freed.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.19-1 (forky)linux 6.12.19-1 (forky)
linuxlinux
linuxlinux>= cc5b9b48d44756a87170f3901c6c2fd99e6b89b2 < aed1bc673907e3df372b317c10ff2f3582f8bf1aaed1bc673907e3df372b317c10ff2f3582f8bf1a
linuxlinux>= cc5b9b48d44756a87170f3901c6c2fd99e6b89b2 < 8cb0eef46d70a99c88c26a1addb7fd955242e0e68cb0eef46d70a99c88c26a1addb7fd955242e0e6
linuxlinux>= cc5b9b48d44756a87170f3901c6c2fd99e6b89b2 < f0df225d12fcb049429fb5bf5122afe143c2dd15f0df225d12fcb049429fb5bf5122afe143c2dd15
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 6.12 < 6.12.186.12.18
linuxlinux_kernel>= 6.13 < 6.13.66.13.6

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.