CVE-2025-21735
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-21735 affects the Linux kernel's NFC (Near Field Communication) subsystem, specifically in the ncihcicreate_pipe() function. The vulnerability was discovered in January 2025 and disclosed in February 2025. The issue occurs when handling the 'pipe' variable, which is received from the network as a u8 data type (Ubuntu Security, Kernel Commit).

Technical details

The vulnerability stems from insufficient bounds checking in the ncihcicreatepipe() function within the NFC subsystem. When the 'pipe' variable, received as a u8 from the network, exceeds 127, it can lead to memory corruption in the caller function ncihciconnectgate(). The issue was fixed by adding bounds checking against NCIHCIMAXPIPES and returning NCIHCIINVALIDPIPE when the value is out of bounds (Kernel Commit). The vulnerability has been assigned a CVSS score of 7.8 (High) (Ubuntu Security).

Impact

If successfully exploited, this vulnerability can result in memory corruption in the Linux kernel's NFC subsystem. This could potentially lead to system crashes, information disclosure, or privilege escalation depending on the specific exploitation scenario (Ubuntu Security).

Mitigation and workarounds

The vulnerability has been patched in the Linux kernel by adding proper bounds checking in the ncihcicreate_pipe() function. System administrators should update their kernel to a version containing the fix. The patch has been backported to various stable kernel branches (Kernel Commit).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40343MEDIUM6.4
  • Linux KernelLinux Kernel
  • kernel-rt-modules-internal
NoYesDec 09, 2025
CVE-2025-40342MEDIUM6.4
  • Linux KernelLinux Kernel
  • kernel-debug-modules-extra
NoYesDec 09, 2025
CVE-2025-40341MEDIUM5.1
  • Linux KernelLinux Kernel
  • linux-nvidia-tegra
NoYesDec 09, 2025
CVE-2025-40345N/AN/A
  • Linux KernelLinux Kernel
  • kernel-headers
NoYesDec 12, 2025
CVE-2025-40344N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management