目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-21682— Linux kernel 代码问题漏洞

一分钟漏洞结论

影响对象
Linux Linux
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在代码问题漏洞,该漏洞源于bnxt驱动在XDP被禁用后未正确重新计算网络设备特性,可能导致硬件GRO功能未正确恢复,进而引发内核崩溃。

CVSS 7.3 · High EPSS 0.23% · P14

影响版本矩阵 10

厂商产品 版本范围状态
Linux Linux 1054aee82321483dceabbb9b9e5d6512e8fe684b< 076a694a42ae3f0466bc6e4126050eeb7b7d299a affected
1054aee82321483dceabbb9b9e5d6512e8fe684b< 90336fc3d6f5e716ac39a9ddbbde453e23a5aa65 affected
1054aee82321483dceabbb9b9e5d6512e8fe684b< 08831a894d18abfaabb5bbde7c2069a7fb41dd93 affected
1054aee82321483dceabbb9b9e5d6512e8fe684b< f0aa6a37a3dbb40b272df5fc6db93c114688adcd affected
4.16 affected
< 4.16 unaffected
6.1.167≤ 6.1.* unaffected
6.6.130≤ 6.6.* unaffected
… +2 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2025-21682 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
eth: bnxt: always recalculate features after XDP clearing, fix null-deref
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: always recalculate features after XDP clearing, fix null-deref Recalculate features when XDP is detached. Before: # ip li set dev eth0 xdp obj xdp_dummy.bpf.o sec xdp # ip li set dev eth0 xdp off # ethtool -k eth0 | grep gro rx-gro-hw: off [requested on] After: # ip li set dev eth0 xdp obj xdp_dummy.bpf.o sec xdp # ip li set dev eth0 xdp off # ethtool -k eth0 | grep gro rx-gro-hw: on The fact that HW-GRO doesn't get re-enabled automatically is just a minor annoyance. The real issue is that the features will randomly come back during another reconfiguration which just happens to invoke netdev_update_features(). The driver doesn't handle reconfiguring two things at a time very robustly. Starting with commit 98ba1d931f61 ("bnxt_en: Fix RSS logic in __bnxt_reserve_rings()") we only reconfigure the RSS hash table if the "effective" number of Rx rings has changed. If HW-GRO is enabled "effective" number of rings is 2x what user sees. So if we are in the bad state, with HW-GRO re-enablement "pending" after XDP off, and we lower the rings by / 2 - the HW-GRO rings doing 2x and the ethtool -L doing / 2 may cancel each other out, and the: if (old_rx_rings != bp->hw_resc.resv_rx_rings && condition in __bnxt_reserve_rings() will be false. The RSS map won't get updated, and we'll crash with: BUG: kernel NULL pointer dereference, address: 0000000000000168 RIP: 0010:__bnxt_hwrm_vnic_set_rss+0x13a/0x1a0 bnxt_hwrm_vnic_rss_cfg_p5+0x47/0x180 __bnxt_setup_vnic_p5+0x58/0x110 bnxt_init_nic+0xb72/0xf50 __bnxt_open_nic+0x40d/0xab0 bnxt_open_nic+0x2b/0x60 ethtool_set_channels+0x18c/0x1d0 As we try to access a freed ring. The issue is present since XDP support was added, really, but prior to commit 98ba1d931f61 ("bnxt_en: Fix RSS logic in __bnxt_reserve_rings()") it wasn't causing major issues.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 代码问题漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在代码问题漏洞,该漏洞源于bnxt驱动在XDP被禁用后未正确重新计算网络设备特性,可能导致硬件GRO功能未正确恢复,进而引发内核崩溃。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Linux Linux 1054aee82321483dceabbb9b9e5d6512e8fe684b ~ 076a694a42ae3f0466bc6e4126050eeb7b7d299a -
Linux Linux 4.16 -

二、漏洞 CVE-2025-21682 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-21682 的情报信息

登录查看更多情报信息。

CVE-2025-21682 补丁与修复 (4)

同批安全公告 · Linux · 2025-01-31 · 共 20 条

CVE-2025-21673 9.8 CRITICAL Linux kernel 资源管理错误漏洞
CVE-2025-21680 7.8 HIGH Linux kernel 输入验证错误漏洞
CVE-2025-21669 7.8 HIGH Linux kernel 代码问题漏洞
CVE-2025-21677 7.8 HIGH Linux kernel 安全漏洞
CVE-2025-21678 7.8 HIGH Linux kernel 安全漏洞
CVE-2025-21676 7.5 HIGH Linux kernel 代码问题漏洞
CVE-2025-21679 Linux kernel 安全漏洞
CVE-2025-21675 Linux kernel 代码问题漏洞
CVE-2025-21674 Linux kernel 安全漏洞
CVE-2025-21681 Linux kernel 安全漏洞
CVE-2025-21672 Linux kernel 安全漏洞
CVE-2025-21671 Linux kernel 资源管理错误漏洞
CVE-2025-21670 Linux kernel 代码问题漏洞
CVE-2025-21683 Linux kernel 安全漏洞
CVE-2025-21668 Linux kernel 安全漏洞
CVE-2025-21667 Linux kernel 安全漏洞
CVE-2025-21666 Linux kernel 代码问题漏洞
CVE-2025-21665 Linux kernel 安全漏洞
CVE-2024-57948 Linux kernel 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-21682

暂无评论


发表评论