PT-2025-4357 · Linux+6 · Linux Kernel+6

Kevin Groeneveld

·

Published

2025-01-13

·

Updated

2026-03-13

·

CVE-2025-21676

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.73/6.12.10
Description The issue is related to a null pointer dereference in the page pool dev alloc pages() function of the Linux kernel's drivers/net/ethernet/freescale/fec main.c module. This can occur when the system is under memory pressure, and the fec enet update cbd function calls page pool dev alloc pages but does not handle the case when it returns NULL. As a result, the kernel may crash. The problem can be reproduced with some frequency when writing over a smbd share to a SATA HDD attached to an imx6q. Setting /proc/sys/vm/min free kbytes to higher values seems to solve the problem for some test cases.
Recommendations To resolve the issue, update the Linux kernel to a version that includes the fix for the page pool dev alloc pages error handling. As a temporary workaround, consider setting /proc/sys/vm/min free kbytes to higher values to minimize the risk of the kernel crashing due to memory allocation errors. Additionally, dropping the current packet when an allocation error occurs can help prevent the kernel from crashing.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12647
ALT-PU-2025-3467
ALT-PU-2025-3500
AZL-56387
BDU:2025-01479
CVE-2025-21676
ECHO-B78E-AF8B-D786
OESA-2025-1594
OESA-2025-1595
OPENSUSE-SU-2025_0428-1
OPENSUSE-SU-2025_0499-1
OPENSUSE-SU-2025_0557-1
SUSE-SU-2025:0428-1
SUSE-SU-2025:0499-1
SUSE-SU-2025:0557-1
SUSE-SU-2025:0564-1
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0428-1
SUSE-SU-2025_0499-1
SUSE-SU-2025_0557-1
USN-7445-1
USN-7448-1
USN-7595-1
USN-7595-2
USN-7595-3
USN-7595-4
USN-7595-5
USN-7596-1
USN-7596-2
USN-7653-1

Affected Products

Alt Linux
Astra Linux
Debian
Linuxmint
Linux Kernel
Suse
Ubuntu