SB20250402117 - Resource management error in Linux kernel hns3 hns3pf driver
Published: April 2, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2025-21924)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the hclge_ptp_init() function in drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_ptp.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/21dba813d9821687a7f9aff576798ba21a859a32
- https://git.kernel.org/stable/c/2c04e507f3a5c5dc6e2b9ab37d8cdedee1ef1a37
- https://git.kernel.org/stable/c/33244e98aa9503585e585335fe2ceb4492630949
- https://git.kernel.org/stable/c/9cfc43c0e6e6a31122b4008d763a2960c206aa2d
- https://git.kernel.org/stable/c/b7365eab39831487a84e63a9638209b68dc54008
- https://git.kernel.org/stable/c/b7d8d4529984e2d4a72a6d552fb886233e8e83cb
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.179