CVE-2025-21957

Aliases:UBUNTU-CVE-2025-21957DEBIAN-CVE-2025-21957
Advisory lineage Upstream: 0 Downstream: 57
Modified
Published: 01 Apr 2025, 15:46
Last modified:11 May 2026, 21:09

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.23% LOW
0% probability +0.14%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Apr 2025, 15:46
Published
Vulnerability first disclosed
11 May 2026, 21:09
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: qla1280: Fix kernel oops when debug level > 2 A null dereference or oops exception will eventually occur when qla1280.c driver is compiled with DEBUG_QLA1280 enabled and ql_debug_level > 2. I think its clear from the code that the intention here is sg_dma_len(s) not length of sg_next(s) when printing the debug info.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.23% Percentile: 14%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • debianlinux

    < 5.10.237-1 | < 6.1.133-1 | < 6.12.20-1 | < 6.12.20-1

  • debianlinux-6.1

    < 6.1.137-1~deb11u1

  • ubuntulinux

    all | < 5.4.0-218.238 | < 5.15.0-142.152 | < 6.8.0-84.84

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    all | < 5.4.0-1147.157 | < 5.15.0-1086.93 | < 6.8.0-1039.41

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    < 5.15.0-1086.93~20.04.1

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    < 5.4.0-1147.157~18.04.1

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    < 6.8.0-1039.41~22.04.1

  • ubuntulinux-aws-fips

    all | < 5.4.0-1147.157+fips1 | < 5.15.0-1086.93+fips1 | < 6.8.0-1039.41+fips1

  • ubuntulinux-aws-hwe

    all

  • ubuntulinux-azure

    all | all | < 5.4.0-1152.159 | < 5.15.0-1091.100 | < 6.8.0-1038.44

  • ubuntulinux-azure-4.15

    all

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    < 5.15.0-1091.100~20.04.1

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    < 5.4.0-1152.159~18.04.1

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    < 6.11.0-1018.18~24.04.1

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-6.8

    < 6.8.0-1036.42~22.04.1

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | all

  • ubuntulinux-azure-fde-5.15

    < 5.15.0-1114.123~20.04.1

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fde-6.2

    all

  • ubuntulinux-azure-fips

    all | < 5.4.0-1153.160+fips1 | < 5.15.0-1091.100+fips1 | < 6.8.0-1040.46+fips1

  • ubuntulinux-azure-nvidia

    < 6.8.0-1025.27

  • ubuntulinux-bluefield

    all | < 5.4.0-1106.113 | < 5.15.0-1069.71

  • ubuntulinux-fips

    all | < 5.4.0-1121.131 | < 5.15.0-142.152+fips1 | < 6.8.0-84.84+fips1

  • ubuntulinux-gcp

    all | all | < 5.4.0-1150.159 | < 5.15.0-1085.94 | < 6.8.0-1040.42

  • ubuntulinux-gcp-4.15

    all

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.15

    < 5.15.0-1085.94~20.04.1

  • ubuntulinux-gcp-5.19

    all

  • ubuntulinux-gcp-5.3

    all

  • ubuntulinux-gcp-5.4

    < 5.4.0-1150.159~18.04.1

  • ubuntulinux-gcp-5.8

    all

  • ubuntulinux-gcp-6.11

    < 6.11.0-1016.16~24.04.1

Showing first 50 affected entries in server-rendered view.

References (53)