Answer in brief
CVE-2025-21954 records a Unknown severity vulnerability in netmem: prevent TX of unreadable skbs. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=65249feb6b3df9e17bab5911ee56fa7b0971e231 <454825019d2f0c59e5174ece9e713f45ad80beff || >=65249feb6b3df9e17bab5911ee56fa7b0971e231 <1c17c8ced25c5fbe424c7ad7ea11d33014a986b1 || >=65249feb6b3df9e17bab5911ee56fa7b0971e231 <f3600c867c99a2cc8038680ecf211089c50e7971 | 454825019d2f0c59e5174ece9e713f45ad80beff, 1c17c8ced25c5fbe424c7ad7ea11d33014a986b1, f3600c867c99a2cc8038680ecf211089c50e7971 |
| Linux/Linuxgeneric | 6.12 | Not reported |
Published upstream
Apr 1, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: netmem: prevent TX of unreadable skbs Currently on stable trees we have support for netmem/devmem RX but not TX. It is not safe to forward/redirect an RX unreadable netmem packet into the device's TX path, as the device may call dma-mapping APIs on dma addrs that should not be passed to it. Fix this by preventing the xmit of unreadable skbs. Tested by configuring tc redirect: sudo tc qdisc add dev eth1 ingress sudo tc filter add dev eth1 ingress protocol ip prio 1 flower ip_proto \ tcp src_ip 192.168.1.12 action mirred egress redirect dev eth1 Before, I see unreadable skbs in the driver's TX path passed to dma mapping APIs. After, I don't see unreadable skbs in the driver's TX path passed to dma mapping APIs.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-21954 records a Unknown severity vulnerability in netmem: prevent TX of unreadable skbs. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=65249feb6b3df9e17bab5911ee56fa7b0971e231 <454825019d2f0c59e5174ece9e713f45ad80beff || >=65249feb6b3df9e17bab5911ee56fa7b0971e231 <1c17c8ced25c5fbe424c7ad7ea11d33014a986b1 || >=65249feb6b3df9e17bab5911ee56fa7b0971e231 <f3600c867c99a2cc8038680ecf211089c50e7971 | 454825019d2f0c59e5174ece9e713f45ad80beff, 1c17c8ced25c5fbe424c7ad7ea11d33014a986b1, f3600c867c99a2cc8038680ecf211089c50e7971 |
| Linux/Linuxgeneric | 6.12 | Not reported |
Published upstream
Apr 1, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: netmem: prevent TX of unreadable skbs Currently on stable trees we have support for netmem/devmem RX but not TX. It is not safe to forward/redirect an RX unreadable netmem packet into the device's TX path, as the device may call dma-mapping APIs on dma addrs that should not be passed to it. Fix this by preventing the xmit of unreadable skbs. Tested by configuring tc redirect: sudo tc qdisc add dev eth1 ingress sudo tc filter add dev eth1 ingress protocol ip prio 1 flower ip_proto \ tcp src_ip 192.168.1.12 action mirred egress redirect dev eth1 Before, I see unreadable skbs in the driver's TX path passed to dma mapping APIs. After, I don't see unreadable skbs in the driver's TX path passed to dma mapping APIs.
Quoted source text, attributed separately from HOL analysis.