cbcvebase.
CVE-2025-21934
published 2025-04-01

CVE-2025-21934: In the Linux kernel, the following vulnerability has been resolved: rapidio: fix an API misues when rio_add_net() fails rio_add_net() calls device_register()…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.20%
10.3th percentile
In the Linux kernel, the following vulnerability has been resolved: rapidio: fix an API misues when rio_add_net() fails rio_add_net() calls device_register() and fails when device_register() fails. Thus, put_device() should be used rather than kfree(). Add "mport->net = NULL;" to avoid a use after free issue.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= e8de370188d098bb49483c287b44925957c3c9b6 < d4ec862ce80f64db923a1d942b5d11cf6fc87d36d4ec862ce80f64db923a1d942b5d11cf6fc87d36
linuxlinux>= e8de370188d098bb49483c287b44925957c3c9b6 < 88ddad53e4cfb6de861c6d4fb7b25427f46baed588ddad53e4cfb6de861c6d4fb7b25427f46baed5
linuxlinux>= e8de370188d098bb49483c287b44925957c3c9b6 < cdd9f58f7fe41a55fae4305ea51fc234769fd466cdd9f58f7fe41a55fae4305ea51fc234769fd466
linuxlinux>= e8de370188d098bb49483c287b44925957c3c9b6 < a5f5e520e8fbc6294020ff8afa36f684d92c6e6aa5f5e520e8fbc6294020ff8afa36f684d92c6e6a
linuxlinux>= e8de370188d098bb49483c287b44925957c3c9b6 < 2537f01d57f08c527e40bbb5862aa6ff433448982537f01d57f08c527e40bbb5862aa6ff43344898
linuxlinux>= e8de370188d098bb49483c287b44925957c3c9b6 < 22e4977141dfc6d109bf29b495bf2187b425099022e4977141dfc6d109bf29b495bf2187b4250990
linuxlinux>= e8de370188d098bb49483c287b44925957c3c9b6 < f0aa4ee1cbbf7789907e5a3f6810de01c146c211f0aa4ee1cbbf7789907e5a3f6810de01c146c211
linuxlinux>= e8de370188d098bb49483c287b44925957c3c9b6 < b2ef51c74b0171fde7eb69b6152d3d2f743ef269b2ef51c74b0171fde7eb69b6152d3d2f743ef269
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 4.6 < 5.4.2915.4.291
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1316.1.131
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.76.13.7
linuxlinux_kernel>= 6.2 < 6.6.836.6.83

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.