cbcvebase.
CVE-2025-21957
published 2025-04-01

CVE-2025-21957: In the Linux kernel, the following vulnerability has been resolved: scsi: qla1280: Fix kernel oops when debug level > 2 A null dereference or oops exception…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.21%
10.7th percentile
In the Linux kernel, the following vulnerability has been resolved: scsi: qla1280: Fix kernel oops when debug level > 2 A null dereference or oops exception will eventually occur when qla1280.c driver is compiled with DEBUG_QLA1280 enabled and ql_debug_level > 2. I think its clear from the code that the intention here is sg_dma_len(s) not length of sg_next(s) when printing the debug info.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= a0441891373fe2db582075a4639fdfcccea470c1 < afa27b7c17a48e01546ccaad0ab017ad0496a522afa27b7c17a48e01546ccaad0ab017ad0496a522
linuxlinux>= a0441891373fe2db582075a4639fdfcccea470c1 < 11a8dac1177a596648a020a7f3708257a2f95fee11a8dac1177a596648a020a7f3708257a2f95fee
linuxlinux>= a0441891373fe2db582075a4639fdfcccea470c1 < c737e2a5fb7f90b96a96121da1b50a9c74ae9b8cc737e2a5fb7f90b96a96121da1b50a9c74ae9b8c
linuxlinux>= a0441891373fe2db582075a4639fdfcccea470c1 < 24602e2664c515a4f2950d7b52c3d5997463418c24602e2664c515a4f2950d7b52c3d5997463418c
linuxlinux>= a0441891373fe2db582075a4639fdfcccea470c1 < ea371d1cdefb0951c7127a33bcd7eb931cf44571ea371d1cdefb0951c7127a33bcd7eb931cf44571
linuxlinux>= a0441891373fe2db582075a4639fdfcccea470c1 < af71ba921d08c241a817010f96458dc5e5e26762af71ba921d08c241a817010f96458dc5e5e26762
linuxlinux>= a0441891373fe2db582075a4639fdfcccea470c1 < 7ac2473e727d67a38266b2b7e55c752402ab588c7ac2473e727d67a38266b2b7e55c752402ab588c
linuxlinux>= a0441891373fe2db582075a4639fdfcccea470c1 < 5233e3235dec3065ccc632729675575dbe3c6b8a5233e3235dec3065ccc632729675575dbe3c6b8a
linuxlinux_kernel< 5.4.2925.4.292
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 0 < 5.4.0-218.2385.4.0-218.238
linuxlinux_kernel>= 5.11 < 5.15.1805.15.180
linuxlinux_kernel>= 5.16 < 6.1.1326.1.132
linuxlinux_kernel>= 5.5 < 5.10.2365.10.236
linuxlinux_kernel>= 6.13 < 6.13.86.13.8
linuxlinux_kernel>= 6.2 < 6.6.846.6.84

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.