Security readout for executives and security teams
Plain-English summary
A Linux Ethernet driver can assign the wrong IOMMU identifier to secondary NVIDIA Tegra MGBE controllers. Bringing up a controller other than MGBE0 may stall networking and panic the kernel, causing an outage. The supplied evidence does not demonstrate data theft, modification, or remote code execution.
Executive priority
Treat affected Tegra systems as an urgent availability risk, especially where secondary Ethernet ports support production, safety, or edge operations. Prioritize patch verification and controlled rollout. Systems without Tegra MGBE hardware or without non-MGBE0 use are not shown by these sources to share this exposure.
Technical view
The dwmac-tegra driver hard-codes MGBE0’s Stream ID instead of reading each controller’s SID from the device tree. On non-MGBE0 interfaces, the incorrect IOMMU configuration can produce transmit timeouts, softirq and RCU stalls, and kernel panic. The cited stable-kernel commits correct the SID handling.
Likely exposure
Exposure is limited to Linux systems using NVIDIA Tegra MGBE controllers, particularly enabled ports other than MGBE0. The supplied affected-version data names 6.2, 6.6.72, 6.12.10, and 6.13 but is ambiguous; verify vendor backports and commit inclusion. Other hardware is not identified as affected.
Exploitation context
CISA KEV status is false, and the bundle provides no evidence of active exploitation or a deliberate remote attack. The documented failure occurs when an Ethernet cable activates MGBE1. Although the supplied CVSS vector specifies network attack, the narrative does not establish attacker-controlled network traffic as a trigger.
Researcher notes
The metadata assigns critical severity and CVSS 10, including high confidentiality and integrity impact. However, the supplied technical narrative demonstrates availability failure only. The affected-version list also contains an unexplained “0” and duplicate commit hashes. Commit-level or distribution-advisory verification is therefore more reliable than the version list alone.
Mitigation direction
Install the vendor or distribution kernel update containing the applicable cited stable-kernel fix.
Confirm the update includes the patch; distribution version strings may conceal backports.
Until patched, disable unused non-MGBE0 interfaces where operationally acceptable.
Consult NVIDIA and Linux distribution guidance before changing production Tegra networking configurations.
Validation and detection
Inventory NVIDIA Tegra systems using dwmac-tegra and identify enabled MGBE controllers other than MGBE0.
Compare running-kernel patch status with the three cited stable-kernel commits.
Review logs for NETDEV WATCHDOG timeouts, adapter resets, RCU stalls, and kernel panics.
In controlled testing, verify secondary MGBE links operate without transmit timeouts or stalls after updating.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-21663 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
0ADP providers
4Source links
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.