Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-21675— net/mlx5: Clear port select structure when fail to create

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在代码问题漏洞,该漏洞源于mlx5_lag_port_sel_create函数在创建端口选择结构失败时,未正确清理已分配的资源,导致在后续尝试重新创建时可能重复销毁资源,引发内核崩溃。

AI Predicted 5.5 Difficulty: Moderate EPSS 0.22% · P13

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 10

VendorProduct Version RangeStatus
Linux Linux dc48516ec7d369c6b80bf9f14d774287b6c428aa< efc92a260e23cf9fafb0b6f6c9beb6f8df93fab4 affected
dc48516ec7d369c6b80bf9f14d774287b6c428aa< 473bc285378f49aa27e5b3e95a6d5ed12995d654 affected
dc48516ec7d369c6b80bf9f14d774287b6c428aa< 1f6e619ef2a4def555b14ac2aeb4304bfccad59b affected
dc48516ec7d369c6b80bf9f14d774287b6c428aa< 5641e82cb55b4ecbc6366a499300917d2f3e6790 affected
5.16 affected
< 5.16 unaffected
6.1.127≤ 6.1.* unaffected
6.6.74≤ 6.6.* unaffected
… +2 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-21675

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
net/mlx5: Clear port select structure when fail to create
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clear port select structure when fail to create Clear the port select structure on error so no stale values left after definers are destroyed. That's because the mlx5_lag_destroy_definers() always try to destroy all lag definers in the tt_map, so in the flow below lag definers get double-destroyed and cause kernel crash: mlx5_lag_port_sel_create() mlx5_lag_create_definers() mlx5_lag_create_definer() <- Failed on tt 1 mlx5_lag_destroy_definers() <- definers[tt=0] gets destroyed mlx5_lag_port_sel_create() mlx5_lag_create_definers() mlx5_lag_create_definer() <- Failed on tt 0 mlx5_lag_destroy_definers() <- definers[tt=0] gets double-destroyed Unable to handle kernel NULL pointer dereference at virtual address 0000000000000008 Mem abort info: ESR = 0x0000000096000005 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x05: level 1 translation fault Data abort info: ISV = 0, ISS = 0x00000005, ISS2 = 0x00000000 CM = 0, WnR = 0, TnD = 0, TagAccess = 0 GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 user pgtable: 64k pages, 48-bit VAs, pgdp=0000000112ce2e00 [0000000000000008] pgd=0000000000000000, p4d=0000000000000000, pud=0000000000000000 Internal error: Oops: 0000000096000005 [#1] PREEMPT SMP Modules linked in: iptable_raw bonding ip_gre ip6_gre gre ip6_tunnel tunnel6 geneve ip6_udp_tunnel udp_tunnel ipip tunnel4 ip_tunnel rdma_ucm(OE) rdma_cm(OE) iw_cm(OE) ib_ipoib(OE) ib_cm(OE) ib_umad(OE) mlx5_ib(OE) ib_uverbs(OE) mlx5_fwctl(OE) fwctl(OE) mlx5_core(OE) mlxdevm(OE) ib_core(OE) mlxfw(OE) memtrack(OE) mlx_compat(OE) openvswitch nsh nf_conncount psample xt_conntrack xt_MASQUERADE nf_conntrack_netlink nfnetlink xfrm_user xfrm_algo xt_addrtype iptable_filter iptable_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 br_netfilter bridge stp llc netconsole overlay efi_pstore sch_fq_codel zram ip_tables crct10dif_ce qemu_fw_cfg fuse ipv6 crc_ccitt [last unloaded: mlx_compat(OE)] CPU: 3 UID: 0 PID: 217 Comm: kworker/u53:2 Tainted: G OE 6.11.0+ #2 Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE Hardware name: QEMU KVM Virtual Machine, BIOS 0.0.0 02/06/2015 Workqueue: mlx5_lag mlx5_do_bond_work [mlx5_core] pstate: 60400005 (nZCv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) pc : mlx5_del_flow_rules+0x24/0x2c0 [mlx5_core] lr : mlx5_lag_destroy_definer+0x54/0x100 [mlx5_core] sp : ffff800085fafb00 x29: ffff800085fafb00 x28: ffff0000da0c8000 x27: 0000000000000000 x26: ffff0000da0c8000 x25: ffff0000da0c8000 x24: ffff0000da0c8000 x23: ffff0000c31f81a0 x22: 0400000000000000 x21: ffff0000da0c8000 x20: 0000000000000000 x19: 0000000000000001 x18: 0000000000000000 x17: 0000000000000000 x16: 0000000000000000 x15: 0000ffff8b0c9350 x14: 0000000000000000 x13: ffff800081390d18 x12: ffff800081dc3cc0 x11: 0000000000000001 x10: 0000000000000b10 x9 : ffff80007ab7304c x8 : ffff0000d00711f0 x7 : 0000000000000004 x6 : 0000000000000190 x5 : ffff00027edb3010 x4 : 0000000000000000 x3 : 0000000000000000 x2 : ffff0000d39b8000 x1 : ffff0000d39b8000 x0 : 0400000000000000 Call trace: mlx5_del_flow_rules+0x24/0x2c0 [mlx5_core] mlx5_lag_destroy_definer+0x54/0x100 [mlx5_core] mlx5_lag_destroy_definers+0xa0/0x108 [mlx5_core] mlx5_lag_port_sel_create+0x2d4/0x6f8 [mlx5_core] mlx5_activate_lag+0x60c/0x6f8 [mlx5_core] mlx5_do_bond_work+0x284/0x5c8 [mlx5_core] process_one_work+0x170/0x3e0 worker_thread+0x2d8/0x3e0 kthread+0x11c/0x128 ret_from_fork+0x10/0x20 Code: a9025bf5 aa0003f6 a90363f7 f90023f9 (f9400400) ---[ end trace 0000000000000000 ]---
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在代码问题漏洞,该漏洞源于mlx5_lag_port_sel_create函数在创建端口选择结构失败时,未正确清理已分配的资源,导致在后续尝试重新创建时可能重复销毁资源,引发内核崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux dc48516ec7d369c6b80bf9f14d774287b6c428aa ~ efc92a260e23cf9fafb0b6f6c9beb6f8df93fab4 -
Linux Linux 5.16 -

II. Public POCs for CVE-2025-21675

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-21675

登录查看更多情报信息。

Patches & Fixes for CVE-2025-21675 (4)

Same Patch Batch · Linux · 2025-01-31 · 20 CVEs total

CVE-2025-21673 9.8 CRITICAL smb: client: fix double free of TCP_Server_Info::hostname
CVE-2025-21669 7.8 HIGH vsock/virtio: discard packets if the transport changes
CVE-2025-21680 7.8 HIGH pktgen: Avoid out-of-bounds access in get_imix_entries
CVE-2025-21678 7.8 HIGH gtp: Destroy device along with udp socket's netns dismantle.
CVE-2025-21677 7.8 HIGH pfcp: Destroy device along with udp socket's netns dismantle.
CVE-2025-21676 7.5 HIGH net: fec: handle page_pool_dev_alloc_pages error
CVE-2025-21682 7.3 HIGH eth: bnxt: always recalculate features after XDP clearing, fix null-deref
CVE-2025-21679 btrfs: add the missing error handling inside get_canonical_dev_path
CVE-2025-21674 net/mlx5e: Fix inversion dependency warning while enabling IPsec tunnel
CVE-2025-21681 openvswitch: fix lockup on tx to unregistering netdev with carrier
CVE-2025-21672 afs: Fix merge preference rule failure condition
CVE-2025-21671 zram: fix potential UAF of zram table
CVE-2025-21670 vsock/bpf: return early if transport is not assigned
CVE-2025-21683 bpf: Fix bpf_sk_select_reuseport() memory leak
CVE-2025-21668 pmdomain: imx8mp-blk-ctrl: add missing loop break condition
CVE-2025-21667 iomap: avoid avoid truncating 64-bit offset to 32 bits
CVE-2025-21666 vsock: prevent null-ptr-deref in vsock_*[has_data|has_space]
CVE-2025-21665 filemap: avoid truncating 64-bit offset to 32 bits
CVE-2024-57948 mac802154: check local interfaces before deleting sdata list

IV. Related Vulnerabilities

V. Comments for CVE-2025-21675

No comments yet


Leave a comment