CVE-2025-21855: ibmvnic: Don't reference skb after sending to VIOS
Published Mar 12, 2025
·Updated
ibmvnic: Don't reference skb after sending to VIOS
Affected Software
12 affected components
Linux Kernel
Linux Linux kernel>=4.5<6.1.130
Linux Linux kernel>=6.2<6.6.80
Linux Linux kernel>=6.7<6.12.17
Linux Linux kernel>=6.13<6.13.5
Linux Linux kernel=6.14-rc1
Linux Linux kernel=6.14-rc2
Linux Linux kernel=6.14-rc3
IBM Verify Identity Access<=11.0 - 11.0.2
IBM Security Verify Access<=10.0 - 10.0.9.1
IBM Verify Identity Access Container<=11.0 - 11.0.2
IBM Security Verify Access Container<=10.0 - 10.0.9.1
Event History
Mar 12, 2025
CVE Published
via MITRE·09:42 AM
Data Sourced
via MITRE·09:42 AM
Description
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Data Sourced
via Red Hat·12:23 PM
DescriptionSeverityAffected Software
Apr 9, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Jul 8, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21855?
CVE-2025-21855 is considered a moderate severity vulnerability in the Linux kernel.
2
How does CVE-2025-21855 affect the Linux kernel?
CVE-2025-21855 affects the Linux kernel by improperly referencing socket buffers after they've been sent to the Virtual I/O Server (VIOS).
3
How can I mitigate CVE-2025-21855?
Mitigation for CVE-2025-21855 involves applying the relevant patches provided in the latest Linux kernel updates.
4
Is CVE-2025-21855 related to network performance issues?
Yes, CVE-2025-21855 may lead to potential network performance issues due to the mishandling of transmitted socket buffers.
5
What versions of the Linux kernel are impacted by CVE-2025-21855?
CVE-2025-21855 impacts multiple versions of the Linux kernel, so it is advisable to check the specific version release notes for details.