CVE-2025-21848: nfp: bpf: Add check for nfp_app_ctrl_msg_alloc()
In the Linux kernel, the following vulnerability has been resolved:
nfp: bpf: Add check for nfpappctrlmsgalloc()
Add check for the return value of nfpappctrlmsgalloc() in nfpbpfcmsgalloc() to prevent null pointer dereference.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.82.1-1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.15.179.1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21848?
CVE-2025-21848 has been classified as a moderate severity vulnerability affecting the Linux kernel.
How do I fix CVE-2025-21848?
To fix CVE-2025-21848, you should upgrade to a patched version of the Linux kernel that addresses the vulnerability.
What type of vulnerability is CVE-2025-21848?
CVE-2025-21848 is a null pointer dereference vulnerability found in the Linux kernel.
Which versions of Linux kernel are affected by CVE-2025-21848?
CVE-2025-21848 affects specific versions of the Linux kernel where the vulnerability has not been patched.
What component of Linux is impacted by CVE-2025-21848?
CVE-2025-21848 impacts the network function programming (nfp) component within the Linux kernel.