In the Linux kernel, the following vulnerability has been resolved:
usbnet: ipheth: fix DPE OoB read
Fix an out-of-bounds DPE read, limit the number of processed DPEs to
the amount that fits into the fixed-size NDP16 header.
Security readout for executives and security teams
Plain-English summary
A Linux kernel USB networking driver can read past a fixed-size structure while processing ipheth data. This could expose kernel memory or crash the system. The issue is local, not described as remotely exploitable in the supplied sources.
Executive priority
Treat as high priority for Linux fleets with local-user exposure or USB access. It is less urgent than internet-facing remote code execution, but kernel memory exposure and crash potential justify timely patching.
Technical view
CVE-2025-21741 is a CWE-125 out-of-bounds read in Linux kernel usbnet/ipheth DPE handling. The fix limits processed DPE entries to what fits in the fixed-size NDP16 header. CVSS 3.1 is 7.1 with local attack vector, low privileges, no user interaction, high confidentiality and availability impact.
Likely exposure
Systems running affected Linux kernel versions with the ipheth USB networking driver present or loadable are the relevant exposure. The source bundle does not identify remote network exposure or affected distributions.
Exploitation context
The bundle marks KEV as false and provides no cited evidence of active exploitation. The CVSS vector indicates a local, low-privilege attack path, but no exploit method or weaponized status is supplied.
Researcher notes
Evidence is limited to the CVE record and kernel stable commits. The key behavior is bounds enforcement for DPE processing against the NDP16 header size. No public exploit status, distro-specific package matrix, or runtime detection guidance is provided.
Mitigation direction
Apply Linux kernel updates containing the referenced stable fixes.
Prioritize systems where untrusted local users or USB device access are possible.
Check distribution advisories for exact fixed package versions.
Restrict unnecessary USB networking driver exposure where operationally feasible.
Validation and detection
Inventory Linux kernel versions across endpoints and servers.
Check whether ipheth is present, loadable, or used for USB tethering.
Map installed kernels against vendor fixed versions and advisories.
Confirm patch deployment with post-update kernel version checks.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-125: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-125 · source CWE mapping
Out-of-bounds Read
Out-of-bounds Read represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.