CVE-2025-21903

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-21903
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21903.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-21903
Downstream
Published
2025-04-01T15:40:45.262Z
Modified
2025-11-28T02:34:11.633601Z
Summary
mctp i3c: handle NULL header address
Details

In the Linux kernel, the following vulnerability has been resolved:

mctp i3c: handle NULL header address

daddr can be NULL if there is no neighbour table entry present, in that case the tx packet should be dropped.

saddr will usually be set by MCTP core, but check for NULL in case a packet is transmitted by a different protocol.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21903.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
c8755b29b58ec65be17bcb8c40763d2dcb1f1db5
Fixed
d8be54c35aee29d96d1350b1b6f153be4da37c07
Fixed
740bf9c9b715cc327d34b1e2d4ee79fcd4c47a56
Fixed
cf7ee25e70c6edfac4553d6b671e8b19db1d9573

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.19
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.7