Review reviewHigh

CVE-2025-21719

Linux Linux, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, linux kernel

In the Linux kernel, the following vulnerability has been resolved: ipmr: do not call mr_mfc_uses_dev() for unres entries syzbot found that calling mr_mfc_uses_dev() for unres entries would crash [1], because c->mfc_un.res.minvif / c->mfc_un.res.maxvif alias to "struct sk_buff_head unresolved", which contain two pointers. This code never worked, lets remove it. [1] Unable to handle kernel paging request at virtual address ffff5fff2d536613 KASAN: maybe wild-memory-access in range [0xfffefff96a9b3098-0xfffefff96a9b309f] Modules linked in: CPU: 1 UID: 0 PID: 7321 Comm: syz.0.16 Not tainted 6.1...

CVSS
7.1
EPSS
0.19%
8.96% percentile
CISA KEV
Not listed
Published
2025.02.27
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.19%
Technical severityCVSS 7.1

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ipmr: do not call mr_mfc_uses_dev() for unres entries syzbot found that calling mr_mfc_uses_dev() for unres entries would crash [1], because c->mfc_un.res.minvif / c->mfc_un.res.maxvif alias to "struct sk_buff_head unresolved", which contain two pointers. This code never worked, lets remove it. [1] Unable to handle kernel paging request at virtual address ffff5fff2d536613 KASAN: maybe wild-memory-access in range [0xfffefff96a9b3098-0xfffefff96a9b309f] Modules linked in: CPU: 1 UID: 0 PID: 7321 Comm: syz.0.16 Not tainted 6.1...

Affected product and versions

Product
Linux Linux, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, linux kernel
Affected versions
>= cb167893f41e21e6bd283d78e53489289dc0592d < 71a0fcb68c0a5f3ec912b540cd5d72148e6ee5f1, >= cb167893f41e21e6bd283d78e53489289dc0592d < 53df27fd38f84bd3cd6b004eb4ff3c4903114f1d, >= cb167893f41e21e6bd283d78e53489289dc0592d < 547ef7e8cbb98f966c8719a3e15d4e078aaa9b47, >= cb167893f41e21e6bd283d78e53489289dc0592d < 57177c5f47a8da852f8d76cf6945cf803f8bb9e5, >= cb167893f41e21e6bd283d78e53489289dc0592d < b379b3162ff55a70464c6a934ae9bf0497478a62, >= cb167893f41e21e6bd283d78e53489289dc0592d < a099834a51ccf9bbba3de86a251b3433539abfde, >= cb167893f41e21e6bd283d78e53489289dc0592d < 26bb7d991f04eeef47dfad23e533834995c26f7a, >= cb167893f41e21e6bd283d78e53489289dc0592d < 15a901361ec3fb1c393f91880e1cbf24ec0a88bd, >= 4.20, >= 4.20 < 5.4.291, >= 5.5 < 5.10.235, >= 5.11 < 5.15.179, >= 5.16 < 6.1.129, >= 6.2 < 6.6.76, >= 6.7 < 6.12.13, >= 6.13 < 6.13.2
Fixed versions
5.4.291, 5.10.235, 5.15.179, 6.1.129, 6.6.76, 6.12.13, 6.13.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, linux kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CWE
CWE-125
CVE-2025-21719 — Linux Linux, SIMATIC S7-1500 TM MFP - GNU/Linux subsystem, linux kernel | SECUFOCUS NOW