cbcvebase.
CVE-2025-21917
published 2025-04-01

CVE-2025-21917: In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: Flush the notify_hotplug_work When performing continuous unbind/bind…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.23%
13.7th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: renesas_usbhs: Flush the notify_hotplug_work When performing continuous unbind/bind operations on the USB drivers available on the Renesas RZ/G2L SoC, a kernel crash with the message "Unable to handle kernel NULL pointer dereference at virtual address" may occur. This issue points to the usbhsc_notify_hotplug() function. Flush the delayed work to avoid its execution when driver resources are unavailable.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= bc57381e634782009b1cb2e86b18013699ada576 < 4cd847a7b630a85493d0294ad9542c21aafaa2464cd847a7b630a85493d0294ad9542c21aafaa246
linuxlinux>= bc57381e634782009b1cb2e86b18013699ada576 < 394965f90454d6f00fe11879142b720c6c1a872e394965f90454d6f00fe11879142b720c6c1a872e
linuxlinux>= bc57381e634782009b1cb2e86b18013699ada576 < 3248c1f833f924246cb98ce7da4569133c1b22923248c1f833f924246cb98ce7da4569133c1b2292
linuxlinux>= bc57381e634782009b1cb2e86b18013699ada576 < 4ca078084cdd5f32d533311d6a0b63a60dcadd414ca078084cdd5f32d533311d6a0b63a60dcadd41
linuxlinux>= bc57381e634782009b1cb2e86b18013699ada576 < d50f5c0cd949593eb9a3d822b34d7b50046a06b7d50f5c0cd949593eb9a3d822b34d7b50046a06b7
linuxlinux>= bc57381e634782009b1cb2e86b18013699ada576 < e5aac1c9b2974636db7ce796ffa6de88fa08335ee5aac1c9b2974636db7ce796ffa6de88fa08335e
linuxlinux>= bc57381e634782009b1cb2e86b18013699ada576 < 830818c8e70c0364e377f0c243b28061ef7967eb830818c8e70c0364e377f0c243b28061ef7967eb
linuxlinux>= bc57381e634782009b1cb2e86b18013699ada576 < 552ca6b87e3778f3dd5b87842f95138162e16c82552ca6b87e3778f3dd5b87842f95138162e16c82
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 3.0 < 5.4.2915.4.291
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1316.1.131
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.76.13.7
linuxlinux_kernel>= 6.2 < 6.6.836.6.83

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.