PT-2025-8990 · Linux+6 · Linux Kernel+6
Published
2025-01-20
·
Updated
2026-04-20
·
CVE-2025-21799
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A vulnerability has been identified in the Linux kernel related to the
am65-cpsw driver. The issue arises when the am65 cpsw nuss remove tx chns() function attempts to free an invalid IRQ, leading to a kernel warning. This occurs when the k3 udma glue tx get irq() function returns a negative error value, which is not properly checked. The problem is triggered when a user invokes the .set channels function, resulting in a call chain that includes am65 cpsw set channels(), am65 cpsw nuss update tx rx chns(), am65 cpsw nuss remove tx chns(), and am65 cpsw nuss init tx chns(). If am65 cpsw nuss init tx chns() fails, it sets tx chn->irq to a negative value, which is then attempted to be freed, causing the warning.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu