#VU106690 NULL pointer dereference in Linux kernel - CVE-2025-21973
Published: April 2, 2025 / Updated: May 11, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the bnxt_get_queue_stats_rx() and bnxt_get_queue_stats_tx() functions in drivers/net/ethernet/broadcom/bnxt/bnxt.c. A local user can perform a denial of service (DoS) attack.
Remediation
External links
- https://git.kernel.org/stable/c/adb830085f0fc3a09a0fc8b64fed2e7c8d244665
- https://git.kernel.org/stable/c/f059a0fd733078c3832fd0f3a3037aa5975d3d36
- https://git.kernel.org/stable/c/f09af5fdfbd9b0fcee73aab1116904c53b199e97
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.20
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.8
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14