THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-21717 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: add missing cpu_to_node to kvzalloc_node in mlx5e_open_xdpredirect_sq kvzalloc_node is not doing a runtime check on the node argument (__alloc_pages_node_noprof does have a VM_BUG_ON, but it expands

[NVD] CVE-2025-21717 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: add missing cpu_to_node to kvzalloc_node in mlx5e_open_xdpredirect_sq kvzalloc_node is not doing a runtime check on the node argument (__alloc_pages_node_noprof does have a VM_BUG_ON, but it expands

lownvdPublished 2025-02-27

CVE-2025-21717 CVSS: 7.8 HIGH Published: 2025-02-27T02:15:15.373

In the Linux kernel, the following vulnerability has been resolved:

net/mlx5e: add missing cpu_to_node to kvzalloc_node in mlx5e_open_xdpredirect_sq

kvzalloc_node is not doing a runtime check on the node argument (__alloc_pages_node_noprof does have a VM_BUG_ON, but it expands to nothing on !CONFIG_DEBUG_VM builds), so doing any e

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-21717