CVE-2025-21953NULL Pointer Dereference in Linux

Severity
5.5MEDIUMNVD
OSV7.8
EPSS
0.1%
top 77.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 1
Latest updateMay 20

Description

In the Linux kernel, the following vulnerability has been resolved: net: mana: cleanup mana struct after debugfs_remove() When on a MANA VM hibernation is triggered, as part of hibernate_snapshot(), mana_gd_suspend() and mana_gd_resume() are called. If during this mana_gd_resume(), a failure occurs with HWC creation, mana_port_debugfs pointer does not get reinitialized and ends up pointing to older, cleaned-up dentry. Further in the hibernation path, as part of power_down(), mana_gd_shutdown()

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

NVDlinux/linux_kernel6.136.13.8+1
CVEListV5linux/linux6607c17c6c5e029da03a90085db22daf518232bfa1466112fb6e819261272ad75e7db750a43b78bf+2
debiandebian/linux

Patches

🔴Vulnerability Details

6
OSV
linux-azure-nvidia vulnerabilities2025-05-20
OSV
linux-azure, linux-azure-6.11 vulnerabilities2025-05-07
OSV
linux-azure-6.8 vulnerabilities2025-05-07
OSV
linux-azure vulnerabilities2025-05-07
GHSA
GHSA-j97h-5fwv-4rhj: In the Linux kernel, the following vulnerability has been resolved: net: mana: cleanup mana struct after debugfs_remove() When on a MANA VM hibernat2025-04-01

📋Vendor Advisories

6
Ubuntu
Linux kernel (Azure, N-Series) vulnerabilities2025-05-20
Ubuntu
Linux kernel (Azure) vulnerabilities2025-05-07
Ubuntu
Linux kernel (Azure) vulnerabilities2025-05-07
Ubuntu
Linux kernel (Azure) vulnerabilities2025-05-07
Red Hat
kernel: net: mana: cleanup mana struct after debugfs_remove()2025-04-01
CVE-2025-21953 — NULL Pointer Dereference in Linux | cvebase