CVE-2025-21751
Chainguard vulnerability analysis and mitigation

Overview

CVE-2025-21751 affects the Linux kernel's net/mlx5 hardware steering (HWS) component. The vulnerability was discovered in early 2025 and involves a firmware failure during matcher disconnect flow that can lead to use-after-free and eventual system crash (Kernel Commit).

Technical details

The vulnerability occurs when firmware failure happens during matcher disconnect flow. The error flow of the function reconnects the matcher back and returns an error, which continues running the calling function and eventually frees the matcher that is being disconnected. This leads to a case where there is a freed matcher on the matchers list, which in turn leads to use-after-free and eventual crash. The CVSS v3.1 base score for this vulnerability is 5.5 MEDIUM (NVD).

Impact

The vulnerability can result in system crashes due to use-after-free errors. Additionally, it may lead to bad steering state (e.g., wrong connection between matchers) and resource leakage during resource destruction (Kernel Commit).

Mitigation and workarounds

The issue has been fixed by modifying the error handling flow to not attempt reconnecting the matcher back when firmware commands fail during disconnect. Instead, the system now returns an error immediately. The fix is included in the kernel patch that modifies the matcher disconnect behavior (Kernel Commit).

Additional resources


SourceThis report was generated using AI

Related Chainguard vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22863CRITICAL9.2
  • RustRust
  • deno
NoYesJan 15, 2026
CVE-2026-22864HIGH8.1
  • RustRust
  • deno
NoYesJan 15, 2026
CVE-2026-1002MEDIUM6.9
  • JavaJava
  • apicurio-registry
NoYesJan 15, 2026
CVE-2026-22045MEDIUM5.9
  • WolfiWolfi
  • github.com/traefik/traefik/v2
NoYesJan 15, 2026
CVE-2026-0915N/AN/A
  • WolfiWolfi
  • glibc-langpack-gu
NoYesJan 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management