Memory Management Issue in Linux Kernel's FEC Driver
CVE-2025-21676

5.5MEDIUM

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
31 January 2025

What is CVE-2025-21676?

A vulnerability exists in the Linux kernel's FEC driver where the fec_enet_update_cbd function fails to properly manage memory allocation errors. Specifically, when calling the page_pool_dev_alloc_pages function, a NULL pointer can be used — which leads to system crashes under memory pressure. This issue may not occur frequently but can surface during high-load scenarios, such as writing over a SMB share. The proper fix involves dropping the current packet when a memory allocation error is detected to ensure system stability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 95698ff6177b5f1f13f251da60e7348413046ae4 < 8a0097db0544b658c159ac787319737712063a23

Linux 95698ff6177b5f1f13f251da60e7348413046ae4 < 1425cb829556398f594658512d49292f988a2ab0

Linux 95698ff6177b5f1f13f251da60e7348413046ae4 < 001ba0902046cb6c352494df610718c0763e77a5

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.