SB2025040264 - NULL pointer dereference in Linux kernel broadcom bnxt driver
Published: April 2, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-21973)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the bnxt_get_queue_stats_rx() and bnxt_get_queue_stats_tx() functions in drivers/net/ethernet/broadcom/bnxt/bnxt.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/adb830085f0fc3a09a0fc8b64fed2e7c8d244665
- https://git.kernel.org/stable/c/f059a0fd733078c3832fd0f3a3037aa5975d3d36
- https://git.kernel.org/stable/c/f09af5fdfbd9b0fcee73aab1116904c53b199e97
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.20
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.8
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14