PT-2025-11019 · Linux+5 · Linux Kernel+5

Pierre Riteau

·

Published

2025-02-13

·

Updated

2026-04-20

·

CVE-2025-21857

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Linux kernel versions prior to the fixed version
Description: A NULL pointer dereference issue has been identified in the Linux kernel. The problem arises from incorrect error handling in the tcf exts miss cookie base alloc() function, which calls xa alloc cyclic(). This function can return 1 if the allocation is successful after wrapping, but this return value is treated as an error. As a result, exts->actions is set to NULL and returned to the caller fl change(), which then calls tcf exts validate ex() and subsequently tcf action init() with the NULL exts->actions as an argument, leading to a NULL pointer dereference.
Recommendations: To resolve this issue, update the Linux kernel to a version that includes the fix for the NULL pointer dereference error in the net/sched subsystem. As a temporary workaround, consider disabling the tcf action init() function until a patch is available. Restrict access to the vulnerable cls api module to minimize the risk of exploitation. Avoid using the exts->actions variable in the affected API endpoints until the issue is resolved.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:20095
ALT-PU-2025-12647
ALT-PU-2025-4807
AZL-58511
BDU:2025-12186
CVE-2025-21857
MGASA-2025-0111
MGASA-2025-0112
OESA-2025-1446
OESA-2025-1450
OPENSUSE-SU-2025_1177-1
OPENSUSE-SU-2025_1178-1
OPENSUSE-SU-2025_1180-1
RHSA-2025:20095
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:1177-1
SUSE-SU-2025:1178-1
SUSE-SU-2025:1180-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_1177-1
SUSE-SU-2025_1178-1
SUSE-SU-2025_1180-1
USN-7521-1
USN-7521-2
USN-7521-3
USN-7703-1
USN-7703-2
USN-7703-3
USN-7703-4
USN-7719-1
USN-7737-1

Affected Products

Alt Linux
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu