CVE-2025-21848

Advisory lineage Upstream: 0 Downstream: 57
Modified
Published: 12 Mar 2025, 09:42
Last modified:12 May 2026, 12:04

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.21% LOW
0% probability +0.14%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 Mar 2025, 09:42
Published
Vulnerability first disclosed
12 May 2026, 12:04
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: nfp: bpf: Add check for nfp_app_ctrl_msg_alloc() Add check for the return value of nfp_app_ctrl_msg_alloc() in nfp_bpf_cmsg_alloc() to prevent null pointer dereference.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.21% Percentile: 11%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • linuxlinux

    ≥ ff3d43f7568c82b335d7df2d40a31447c3fce10c, < d64c6ca420019712e194fe095b55f87363e22a9a | ≥ ff3d43f7568c82b335d7df2d40a31447c3fce10c, < e976ea6c5e1b005c64467cbf94a8577aae9c7d81 | ≥ ff3d43f7568c82b335d7df2d40a31447c3fce10c, < 924b239f9704566e0d86abd894d2d64bd73c11eb | ≥ ff3d43f7568c82b335d7df2d40a31447c3fce10c, < 1358d8e07afdf21d49ca6f00c56048442977e00a | ≥ ff3d43f7568c82b335d7df2d40a31447c3fce10c, < 29ccb1e4040da6ff02b7e64efaa2f8e6bf06020d | ≥ ff3d43f7568c82b335d7df2d40a31447c3fce10c, < 897c32cd763fd11d0b6ed024c52f44d2475bb820 | ≥ ff3d43f7568c82b335d7df2d40a31447c3fce10c, < bd97f60750bb581f07051f98e31dfda59d3a783b | ≥ ff3d43f7568c82b335d7df2d40a31447c3fce10c, < 878e7b11736e062514e58f3b445ff343e6705537 | 4.16

  • linuxlinux_kernel

    ≥ 4.16, < 6.1.130 | ≥ 6.2, < 6.6.80 | ≥ 6.7, < 6.12.17 | ≥ 6.13, < 6.13.5 | 6.14:rc1 | 6.14:rc2 | 6.14:rc3

References (11)