Answer in brief
CVE-2025-21735 records a Unknown severity vulnerability in NFC: nci: Add bounds checking in nci_hci_create_pipe(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-21735 records a Unknown severity vulnerability in NFC: nci: Add bounds checking in nci_hci_create_pipe(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a1b0b9415817c14d207921582f269d03f848b69f <bd249109d266f1d52548c46634a15b71656e0d44 || >=a1b0b9415817c14d207921582f269d03f848b69f <674e17c5933779a8bf5c15d596fdfcb5ccdebbc2 || >=a1b0b9415817c14d207921582f269d03f848b69f <10b3f947b609713e04022101f492d288a014ddfa || >=a1b0b9415817c14d207921582f269d03f848b69f <d5a461c315e5ff92657f84d8ba50caa5abf5c22a || >=a1b0b9415817c14d207921582f269d03f848b69f <172cdfc3a5ea20289c58fb73dadc6fd4a8784a4e || >=a1b0b9415817c14d207921582f269d03f848b69f <2ae4bade5a64d126bd18eb66bd419005c5550218 || >=a1b0b9415817c14d207921582f269d03f848b69f <59c7ed20217c0939862fbf8145bc49d5b3a13f4f || >=a1b0b9415817c14d207921582f269d03f848b69f <110b43ef05342d5a11284cc8b21582b698b4ef1c | bd249109d266f1d52548c46634a15b71656e0d44, 674e17c5933779a8bf5c15d596fdfcb5ccdebbc2, 10b3f947b609713e04022101f492d288a014ddfa, d5a461c315e5ff92657f84d8ba50caa5abf5c22a, 172cdfc3a5ea20289c58fb73dadc6fd4a8784a4e, 2ae4bade5a64d126bd18eb66bd419005c5550218, 59c7ed20217c0939862fbf8145bc49d5b3a13f4f, 110b43ef05342d5a11284cc8b21582b698b4ef1c |
| Linux/Linuxgeneric | 4.4 | Not reported |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
Published upstream
Feb 27, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Add bounds checking in nci_hci_create_pipe() The "pipe" variable is a u8 which comes from the network. If it's more than 127, then it results in memory corruption in the caller, nci_hci_connect_gate().
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic), Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystem (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=a1b0b9415817c14d207921582f269d03f848b69f <bd249109d266f1d52548c46634a15b71656e0d44 || >=a1b0b9415817c14d207921582f269d03f848b69f <674e17c5933779a8bf5c15d596fdfcb5ccdebbc2 || >=a1b0b9415817c14d207921582f269d03f848b69f <10b3f947b609713e04022101f492d288a014ddfa || >=a1b0b9415817c14d207921582f269d03f848b69f <d5a461c315e5ff92657f84d8ba50caa5abf5c22a || >=a1b0b9415817c14d207921582f269d03f848b69f <172cdfc3a5ea20289c58fb73dadc6fd4a8784a4e || >=a1b0b9415817c14d207921582f269d03f848b69f <2ae4bade5a64d126bd18eb66bd419005c5550218 || >=a1b0b9415817c14d207921582f269d03f848b69f <59c7ed20217c0939862fbf8145bc49d5b3a13f4f || >=a1b0b9415817c14d207921582f269d03f848b69f <110b43ef05342d5a11284cc8b21582b698b4ef1c | bd249109d266f1d52548c46634a15b71656e0d44, 674e17c5933779a8bf5c15d596fdfcb5ccdebbc2, 10b3f947b609713e04022101f492d288a014ddfa, d5a461c315e5ff92657f84d8ba50caa5abf5c22a, 172cdfc3a5ea20289c58fb73dadc6fd4a8784a4e, 2ae4bade5a64d126bd18eb66bd419005c5550218, 59c7ed20217c0939862fbf8145bc49d5b3a13f4f, 110b43ef05342d5a11284cc8b21582b698b4ef1c |
| Linux/Linuxgeneric | 4.4 | Not reported |
| Siemens/SIMATIC S7-1500 TM MFP - GNU/Linux subsystemgeneric | >=0 <* | * |
Published upstream
Feb 27, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: NFC: nci: Add bounds checking in nci_hci_create_pipe() The "pipe" variable is a u8 which comes from the network. If it's more than 127, then it results in memory corruption in the caller, nci_hci_connect_gate().
Quoted source text, attributed separately from HOL analysis.