SB20250227178 - Resource management error in Linux kernel net usb driver
Published: February 27, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource management error (CVE-ID: CVE-2025-21708)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to resource management error within the MSR_SPEED() and rtl8150_probe() functions in drivers/net/usb/rtl8150.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3c706829ceb6e347bd4ddfd17f1d3048acd69da2
- https://git.kernel.org/stable/c/90b7f2961798793275b4844348619b622f983907
- https://git.kernel.org/stable/c/c843515ad2be7349dd6b60e5fd299d0da0b8458b
- https://git.kernel.org/stable/c/e10b392a7495a5dbbb25247e2c17d380d9899263
- https://git.kernel.org/stable/c/f395b7efcee8df54309eb2d4a624ef13f5d88b66
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.13