SB2025040297 - Improper error handling in Linux kernel llc
Published: April 2, 2025 Updated: May 11, 2025
Security Bulletin ID
SB2025040297
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper error handling (CVE-ID: CVE-2025-21925)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error handling within the llc_sap_action_unitdata_ind(), llc_sap_action_send_ui() and llc_sap_action_send_test_c() functions in net/llc/llc_s_ac.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/056e8a46d79e22983bae4267e0d9c52927076f46
- https://git.kernel.org/stable/c/0f764208dc24ea043c3e20194d32aebf94f8459c
- https://git.kernel.org/stable/c/13f3f872627f0f27c31245524fc11367756240ad
- https://git.kernel.org/stable/c/17f86e25431ebc15aa9245ff156414fdad47822d
- https://git.kernel.org/stable/c/416e8b4c20c6398044e93008deefd563289f477d
- https://git.kernel.org/stable/c/64e6a754d33d31aa844b3ee66fb93ac84ca1565e
- https://git.kernel.org/stable/c/9b6f083db141ece0024be01526aa05aa978811cb
- https://git.kernel.org/stable/c/cd1c44327bbbd50fc24f2b38892f5f328b784d0f
- https://mirrors.edge.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.291