PT-2025-13227 · Linux+4 · Linux Kernel+4

CVE-2025-21890

·

Published

2025-02-26

·

Updated

2026-08-19

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.14.0-smp-DEV #1697
Description The issue is related to the idpf rx rsc() function in the Linux kernel, which uses skb transport offset(skb) before the transport header is set. This triggers a warning for CONFIG DEBUG NET=y builds. The problem is caused by the idpf vport splitq napi poll function, which is linked to the idpf module.
Recommendations For Linux kernel versions prior to 6.14.0-smp-DEV #1697, consider updating to a newer version that includes the fix for the idpf rx rsc() function. As a temporary workaround, consider disabling the idpf module to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12279
CVE-2025-21890
OPENSUSE-SU-2025_1177-1
OPENSUSE-SU-2025_1178-1
OPENSUSE-SU-2025_1180-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:1177-1
SUSE-SU-2025:1178-1
SUSE-SU-2025:1180-1
SUSE-SU-2025:20190-1
SUSE-SU-2025:20192-1
SUSE-SU-2025:20260-1
SUSE-SU-2025:20270-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_1177-1
SUSE-SU-2025_1178-1
SUSE-SU-2025_1180-1
USN-7521-1
USN-7521-2
USN-7521-3
USN-7764-1
USN-7764-2
USN-7765-1
USN-7766-1
USN-7767-1
USN-7767-2
USN-7779-1
USN-7790-1
USN-7800-1
USN-7801-1
USN-7801-2
USN-7801-3
USN-7802-1
USN-7809-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu