{"id":"CVE-2025-21802","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix oops when unload drivers paralleling\n\nWhen unload hclge driver, it tries to disable sriov first for each\nae_dev node from hnae3_ae_dev_list","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix oops when unload drivers paralleling\n\nWhen unload hclge driver, it tries to disable sriov first for each\nae_dev node from hnae3_ae_dev_list. If user unlo…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 4.19.214, < 4.20","linux_kernel >= 5.4.156, < 5.5","linux_kernel >= 5.10.76, < 5.10.235","linux_kernel >= 5.14.15, < 5.15","linux_kernel >= 5.15.1, < 5.15.179","linux_kernel >= 5.16, < 6.1.129","linux_kernel >= 6.2, < 6.6.76","linux_kernel >= 6.7, < 6.12.13","linux_kernel >= 6.13, < 6.13.2","linux_kernel = 5.15"],"patched":["linux_kernel 6.13.2"],"published":"2025-02-27","updated":"2026-07-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-21802","references":[{"url":"https://git.kernel.org/stable/c/622d92a67656e5c4d2d6ccac02d688ed995418c6","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/82736bb83fb0221319c85c2e9917d0189cd84e1e","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8c640dd3d900cc8988a39c007591f1deee776df4","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92e5995773774a3e70257e9c95ea03518268bea5","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b5a8bc47aa0a4aa8bca5466dfa2d12dbb5b3cd0c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cafe9a27e22736d4a01b3933e36225f9857c7988","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e876522659012ef2e73834a0b9f1cbe3f74d5fad","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-019113.html","label":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"}],"tags":["nvd","cve.org"],"epss":0.00201,"epssPercentile":0.10285,"ingestedAt":"2026-07-14T13:36:55.772Z","slug":"CVE-2025-21802","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nnet: hns3: fix oops when unload drivers paralleling\n\nWhen unload hclge driver, it tries to disable sriov first for each\nae_dev node from hnae3_ae_dev_list. If user unloads hns3 driver at\nthe time, because it removes all the ae_dev nodes, and it may cause\noops.\n\nBut we can't simply use hnae3_common_lock for this. Because in the\nprocess flow of pci_disable_sriov(), it will trigger the remove flow\nof VF, which will also take hnae3_common_lock.\n\nTo fixes it, introduce a new mutex to protect the unload process.\n\n## Affected\n\n- `linux_kernel >= 4.19.214, < 4.20`\n- `linux_kernel >= 5.4.156, < 5.5`\n- `linux_kernel >= 5.10.76, < 5.10.235`\n- `linux_kernel >= 5.14.15, < 5.15`\n- `linux_kernel >= 5.15.1, < 5.15.179`\n- `linux_kernel >= 5.16, < 6.1.129`\n- `linux_kernel >= 6.2, < 6.6.76`\n- `linux_kernel >= 6.7, < 6.12.13`\n- `linux_kernel >= 6.13, < 6.13.2`\n- `linux_kernel = 5.15`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.13.2`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}