SB2025020430 - NULL pointer dereference in Linux kernel core lag driver
Published: February 4, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-21675)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the mlx5_lag_port_sel_create() and mlx5_destroy_ttc_table() functions in drivers/net/ethernet/mellanox/mlx5/core/lag/port_sel.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1f6e619ef2a4def555b14ac2aeb4304bfccad59b
- https://git.kernel.org/stable/c/473bc285378f49aa27e5b3e95a6d5ed12995d654
- https://git.kernel.org/stable/c/5641e82cb55b4ecbc6366a499300917d2f3e6790
- https://git.kernel.org/stable/c/efc92a260e23cf9fafb0b6f6c9beb6f8df93fab4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.1.127