cbcvebase.
CVE-2025-21980
published 2025-04-01

CVE-2025-21980: In the Linux kernel, the following vulnerability has been resolved: sched: address a potential NULL pointer dereference in the GRED scheduler. If kzalloc in…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
8.0th percentile
In the Linux kernel, the following vulnerability has been resolved: sched: address a potential NULL pointer dereference in the GRED scheduler. If kzalloc in gred_init returns a NULL pointer, the code follows the error handling path, invoking gred_destroy. This, in turn, calls gred_offload, where memset could receive a NULL pointer as input, potentially leading to a kernel crash. When table->opt is NULL in gred_init(), gred_change_table_def() is not called yet, so it is not necessary to call ->ndo_setup_tc() in gred_offload().

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= f25c0515c521375154c62c72447869f40218c861 < d02c9acd68950a444acda18d514e2b41f846cb7fd02c9acd68950a444acda18d514e2b41f846cb7f
linuxlinux>= f25c0515c521375154c62c72447869f40218c861 < 0f0a152957d64ce45b4c27c687e7d087e8f450790f0a152957d64ce45b4c27c687e7d087e8f45079
linuxlinux>= f25c0515c521375154c62c72447869f40218c861 < 68896dd50180b38ea552e49a6a00b685321e576968896dd50180b38ea552e49a6a00b685321e5769
linuxlinux>= f25c0515c521375154c62c72447869f40218c861 < 5f996b4f80c2cef1f9c77275055e7fcba44c91995f996b4f80c2cef1f9c77275055e7fcba44c9199
linuxlinux>= f25c0515c521375154c62c72447869f40218c861 < 115ef44a98220fddfab37a39a19370497cd718b9115ef44a98220fddfab37a39a19370497cd718b9
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 6.12.20-16.12.20-1
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 5.16 < 6.1.1326.1.132
linuxlinux_kernel>= 6.13 < 6.13.86.13.8
linuxlinux_kernel>= 6.2 < 6.6.846.6.84
linuxlinux_kernel>= 6.7 < 6.12.206.12.20
msrcazl3_kernel_6.6.82.1-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.85.1-2_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.