PT-2025-13227 · Linux+4 · Linux Kernel+4
CVE-2025-21890
·
Published
2025-02-26
·
Updated
2026-08-19
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 6.14.0-smp-DEV #1697
Description
The issue is related to the idpf rx rsc() function in the Linux kernel, which uses skb transport offset(skb) before the transport header is set. This triggers a warning for CONFIG DEBUG NET=y builds. The problem is caused by the idpf vport splitq napi poll function, which is linked to the idpf module.
Recommendations
For Linux kernel versions prior to 6.14.0-smp-DEV #1697, consider updating to a newer version that includes the fix for the idpf rx rsc() function. As a temporary workaround, consider disabling the idpf module to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Astra Linux
Linuxmint
Linux Kernel
Suse
Ubuntu