PT-2025-14302 · Linux+2 · Linux Kernel+2

Published

2025-03-01

·

Updated

2026-01-20

·

CVE-2025-21921

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved, related to the ethtool netlink command. The issue occurs when the ethnl req get phydev() function is used to lookup a phy device, and the header parameter is NULL, causing a crash. This happens in the notify path after a ->set operation, where there are no request attributes available. The vulnerability is triggered when the tb array is NULL, such as in the ethnl notify path, and only affects the PLCA command.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-04086
CVE-2025-21921

Affected Products

Astra Linux
Linux Kernel
Red Os