{"id":"DEBIAN-CVE-2025-21970","details":"In the Linux kernel, the following vulnerability has been resolved:  net/mlx5: Bridge, fix the crash caused by LAG state check  When removing LAG device from bridge, NETDEV_CHANGEUPPER event is triggered. Driver finds the lower devices (PFs) to flush all the offloaded entries. And mlx5_lag_is_shared_fdb is checked, it returns false if one of PF is unloaded. In such case, mlx5_esw_bridge_lag_rep_get() and its caller return NULL, instead of the alive PF, and the flush is skipped.  Besides, the bridge fdb entry's lastuse is updated in mlx5 bridge event handler. But this SWITCHDEV_FDB_ADD_TO_BRIDGE event can be ignored in this case because the upper interface for bond is deleted, and the entry will never be aged because lastuse is never updated.  To make things worse, as the entry is alive, mlx5 bridge workqueue keeps sending that event, which is then handled by kernel bridge notifier. It causes the following crash when accessing the passed bond netdev which is already destroyed.  To fix this issue, remove such checks. LAG state is already checked in commit 15f8f168952f (\"net/mlx5: Bridge, verify LAG state when adding bond to bridge\"), driver still need to skip offload if LAG becomes invalid state after initialization.   Oops: stack segment: 0000 [#1] SMP  CPU: 3 UID: 0 PID: 23695 Comm: kworker/u40:3 Tainted: G           OE      6.11.0_mlnx #1  Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.13.0-0-gf21b5a4aeb02-prebuilt.qemu.org 04/01/2014  Workqueue: mlx5_bridge_wq mlx5_esw_bridge_update_work [mlx5_core]  RIP: 0010:br_switchdev_event+0x2c/0x110 [bridge]  Code: 44 00 00 48 8b 02 48 f7 00 00 02 00 00 74 69 41 54 55 53 48 83 ec 08 48 8b a8 08 01 00 00 48 85 ed 74 4a 48 83 fe 02 48 89 d3 \u003c4c\u003e 8b 65 00 74 23 76 49 48 83 fe 05 74 7e 48 83 fe 06 75 2f 0f b7  RSP: 0018:ffffc900092cfda0 EFLAGS: 00010297  RAX: ffff888123bfe000 RBX: ffffc900092cfe08 RCX: 00000000ffffffff  RDX: ffffc900092cfe08 RSI: 0000000000000001 RDI: ffffffffa0c585f0  RBP: 6669746f6e690a30 R08: 0000000000000000 R09: ffff888123ae92c8  R10: 0000000000000000 R11: fefefefefefefeff R12: ffff888123ae9c60  R13: 0000000000000001 R14: ffffc900092cfe08 R15: 0000000000000000  FS:  0000000000000000(0000) GS:ffff88852c980000(0000) knlGS:0000000000000000  CS:  0010 DS: 0000 ES: 0000 CR0: 0000000080050033  CR2: 00007f15914c8734 CR3: 0000000002830005 CR4: 0000000000770ef0  DR0: 0000000000000000 DR1: 0000000000000000 DR2: 0000000000000000  DR3: 0000000000000000 DR6: 00000000fffe0ff0 DR7: 0000000000000400  PKRU: 55555554  Call Trace:   \u003cTASK\u003e   ? __die_body+0x1a/0x60   ? die+0x38/0x60   ? do_trap+0x10b/0x120   ? do_error_trap+0x64/0xa0   ? exc_stack_segment+0x33/0x50   ? asm_exc_stack_segment+0x22/0x30   ? br_switchdev_event+0x2c/0x110 [bridge]   ? sched_balance_newidle.isra.149+0x248/0x390   notifier_call_chain+0x4b/0xa0   atomic_notifier_call_chain+0x16/0x20   mlx5_esw_bridge_update+0xec/0x170 [mlx5_core]   mlx5_esw_bridge_update_work+0x19/0x40 [mlx5_core]   process_scheduled_works+0x81/0x390   worker_thread+0x106/0x250   ? bh_worker+0x110/0x110   kthread+0xb7/0xe0   ? kthread_park+0x80/0x80   ret_from_fork+0x2d/0x50   ? kthread_park+0x80/0x80   ret_from_fork_asm+0x11/0x20   \u003c/TASK\u003e","modified":"2026-09-01T16:06:10.568887725Z","published":"2025-04-01T16:15:28.323Z","upstream":["CVE-2025-21970"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-21970"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.133-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21970.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21970.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.20-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21970.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}