{"schema_version":"1.9.0","id":"CVE-2025-21957","published":"2025-04-01T15:46:56.733Z","modified":"2026-08-12T03:51:28.925903841Z","related":["SUSE-SU-2025:01600-1","SUSE-SU-2025:01614-1","SUSE-SU-2025:01707-1","SUSE-SU-2025:01919-1","SUSE-SU-2025:01951-1","SUSE-SU-2025:01964-1","SUSE-SU-2025:01967-1","SUSE-SU-2025:20192-1","SUSE-SU-2025:20206-1","SUSE-SU-2025:20270-1","SUSE-SU-2025:20283-1"],"summary":"scsi: qla1280: Fix kernel oops when debug level > 2","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: qla1280: Fix kernel oops when debug level > 2\n\nA null dereference or oops exception will eventually occur when qla1280.c\ndriver is compiled with DEBUG_QLA1280 enabled and ql_debug_level > 2.  I\nthink its clear from the code that the intention here is sg_dma_len(s) not\nlength of sg_next(s) when printing the debug info.","affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"a0441891373fe2db582075a4639fdfcccea470c1"},{"fixed":"afa27b7c17a48e01546ccaad0ab017ad0496a522"},{"fixed":"11a8dac1177a596648a020a7f3708257a2f95fee"},{"fixed":"c737e2a5fb7f90b96a96121da1b50a9c74ae9b8c"},{"fixed":"24602e2664c515a4f2950d7b52c3d5997463418c"},{"fixed":"ea371d1cdefb0951c7127a33bcd7eb931cf44571"},{"fixed":"af71ba921d08c241a817010f96458dc5e5e26762"},{"fixed":"7ac2473e727d67a38266b2b7e55c752402ab588c"},{"fixed":"5233e3235dec3065ccc632729675575dbe3c6b8a"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-21957.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.6.24"},{"fixed":"5.4.292"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.5.0"},{"fixed":"5.10.236"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.180"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.132"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.84"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.20"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.13.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-21957.json"}}],"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/11a8dac1177a596648a020a7f3708257a2f95fee"},{"type":"WEB","url":"https://git.kernel.org/stable/c/24602e2664c515a4f2950d7b52c3d5997463418c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/5233e3235dec3065ccc632729675575dbe3c6b8a"},{"type":"WEB","url":"https://git.kernel.org/stable/c/7ac2473e727d67a38266b2b7e55c752402ab588c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/af71ba921d08c241a817010f96458dc5e5e26762"},{"type":"WEB","url":"https://git.kernel.org/stable/c/afa27b7c17a48e01546ccaad0ab017ad0496a522"},{"type":"WEB","url":"https://git.kernel.org/stable/c/c737e2a5fb7f90b96a96121da1b50a9c74ae9b8c"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ea371d1cdefb0951c7127a33bcd7eb931cf44571"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21957.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-21957"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21957.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}