← All CVEs

CVE-2025-21954

critical · 9.8

In the Linux kernel, the following vulnerability has been resolved: netmem: prevent TX of unreadable skbs Currently on stable trees we have support for netmem/devmem RX but not TX. It is not safe to forward/redirect an RX unreadable netmem packet into the device's TX path, as the device may call dma-mapping APIs on dma addrs that should not be passed to it. Fix this by preventing the xmit of unreadable skbs. Tested by configuring tc redirect: sudo tc qdisc add dev eth1 ingress sudo tc filter add dev eth1 ingress protocol ip prio 1 flower ip_proto \ tcp src_ip 192.168.1.12 action mirred egress redirect dev eth1 Before, I see unreadable skbs in the driver's TX path passed to dma mapping APIs. After, I don't see unreadable skbs in the driver's TX path passed to dma mapping APIs.

9.8
CVSS
0.5%
EPSS (exploit prob.)
41st
EPSS percentile
2025-04-01
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-401

Affected products

VendorProductAffected versions
linuxlinux_kernel>= 6.12, < 6.12.20
linuxlinux_kernel>= 6.13, < 6.13.8
linuxlinux_kernel6.14
linuxlinux_kernel6.14
linuxlinux_kernel6.14
linuxlinux_kernel6.14
linuxlinux_kernel6.14
linuxlinux_kernel6.14

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-21954