CVE-2025-21901

medium

Description

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Add sanity checks on rdev validity There is a possibility that ulp_irq_stop and ulp_irq_start callbacks will be called when the device is in detached state. This can cause a crash due to NULL pointer dereference as the rdev is already freed.

References

https://git.kernel.org/stable/c/f0df225d12fcb049429fb5bf5122afe143c2dd15

https://git.kernel.org/stable/c/aed1bc673907e3df372b317c10ff2f3582f8bf1a

https://git.kernel.org/stable/c/8cb0eef46d70a99c88c26a1addb7fd955242e0e6

Details

Source: Mitre, NVD

Published: 2025-04-01

Updated: 2025-04-15

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.00017