CVE-2025-21662

MEDIUM

Linux Kernel Command Entry Allocation Failure - Denial of Service

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix variable not being completed when function returns When cmd_alloc_index(), fails cmd_work_handler() needs to complete ent->slotted before returning early. Otherwise the task which issued the command may hang: mlx5_core 0000:01:00.0: cmd_work_handler:877:(pid 3880418): failed to allocate command entry INFO: task kworker/13:2:4055883 blocked for more than 120 seconds. Not tainted 4.19.90-25.44.v2101.ky10.aarch64 #1 "echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message. kworker/13:2 D 0 4055883 2 0x00000228 Workqueue: events mlx5e_tx_dim_work [mlx5_core] Call trace: __switch_to+0xe8/0x150 __schedule+0x2a8/0x9b8 schedule+0x2c/0x88 schedule_timeout+0x204/0x478 wait_for_common+0x154/0x250 wait_for_completion+0x28/0x38 cmd_exec+0x7a0/0xa00 [mlx5_core] mlx5_cmd_exec+0x54/0x80 [mlx5_core] mlx5_core_modify_cq+0x6c/0x80 [mlx5_core] mlx5_core_modify_cq_moderation+0xa0/0xb8 [mlx5_core] mlx5e_tx_dim_work+0x54/0x68 [mlx5_core] process_one_work+0x1b0/0x448 worker_thread+0x54/0x468 kthread+0x134/0x138 ret_from_fork+0x10/0x18

Scores

CVSS v3 5.5
EPSS 0.0020
EPSS Percentile 9.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (21)
linux/Kernel < 6.1.125linux
linux/Kernel 6.2.0 - 6.6.72linux
linux/Kernel 6.7.0 - 6.12.10linux
Linux/Linux < 6.10
Linux/Linux 2d0962d05c93de391ce85f6e764df895f47c8918
Linux/Linux 485d65e1357123a697c591a5aeb773994b247ad7 - 0e2909c6bec9048f49d0c8e16887c63b50b14647
Linux/Linux 485d65e1357123a697c591a5aeb773994b247ad7 - 36124081f6ffd9dfaad48830bdf106bb82a9457d
Linux/Linux 4baae687a20ef2b82fde12de3c04461e6f2521d6 - f0a2808767ac39f64b1d9a0ff865c255073cf3d4
Linux/Linux 6.1.125 - 6.1.*
Linux/Linux 6.1.93 - 6.1.125
... and 11 more
Published Jan 21, 2025
Tracked Since Feb 18, 2026