CVE-2025-21848

Source
https://cve.org/CVERecord?id=CVE-2025-21848
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21848.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-21848
Downstream
Related
Published
2025-03-12T09:42:04.263Z
Modified
2026-05-18T05:59:13.420766085Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
nfp: bpf: Add check for nfp_app_ctrl_msg_alloc()
Details

In the Linux kernel, the following vulnerability has been resolved:

nfp: bpf: Add check for nfpappctrlmsgalloc()

Add check for the return value of nfpappctrlmsgalloc() in nfpbpfcmsg_alloc() to prevent null pointer dereference.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21848.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
ff3d43f7568c82b335d7df2d40a31447c3fce10c
Fixed
d64c6ca420019712e194fe095b55f87363e22a9a
Fixed
e976ea6c5e1b005c64467cbf94a8577aae9c7d81
Fixed
924b239f9704566e0d86abd894d2d64bd73c11eb
Fixed
1358d8e07afdf21d49ca6f00c56048442977e00a
Fixed
29ccb1e4040da6ff02b7e64efaa2f8e6bf06020d
Fixed
897c32cd763fd11d0b6ed024c52f44d2475bb820
Fixed
bd97f60750bb581f07051f98e31dfda59d3a783b
Fixed
878e7b11736e062514e58f3b445ff343e6705537

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21848.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.16.0
Fixed
5.4.291
Type
ECOSYSTEM
Events
Introduced
5.5.0
Fixed
5.10.235
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.179
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.130
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.80
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.17
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.5

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21848.json"