CVE-2025-21961: eth: bnxt: fix truesize for mb-xdp-pass case
In the Linux kernel, the following vulnerability has been resolved:
eth: bnxt: fix truesize for mb-xdp-pass case
When mb-xdp is set and return is XDP_PASS, packet is converted from
xdp_buff to sk_buff with xdp_update_skb_shared_info() in
bnxt_xdp_build_skb().
bnxt_xdp_build_skb() passes incorrect truesize argument to
xdp_update_skb_shared_info().
The truesize is calculated as BNXT_RX_PAGE_SIZE * sinfo->nr_frags but
the skb_shared_info was wiped by napi_build_skb() before.
So it stores sinfo->nr_frags before bnxt_xdp_build_skb() and use it
instead of getting skb_shared_info from xdp_get_shared_info_from_buff().
Splat looks like:
------------[ cut here ]------------
WARNING: CPU: 2 PID: 0 at net/core/skbuff.c:6072 skb_try_coalesce+0x504/0x590
Modules linked in: xt_nat xt_tcpudp veth af_packet xt_conntrack nft_chain_nat xt_MASQUERADE nf_conntrack_netlink xfrm_user xt_addrtype nft_coms
CPU: 2 UID: 0 PID: 0 Comm: swapper/2 Not tainted 6.14.0-rc2+ #3
RIP: 0010:skb_try_coalesce+0x504/0x590
Code: 4b fd ff ff 49 8b 34 24 40 80 e6 40 0f 84 3d fd ff ff 49 8b 74 24 48 40 f6 c6 01 0f 84 2e fd ff ff 48 8d 4e ff e9 25 fd ff ff <0f> 0b e99
RSP: 0018:ffffb62c4120caa8 EFLAGS: 00010287
RAX: 0000000000000003 RBX: ffffb62c4120cb14 RCX: 0000000000000ec0
RDX: 0000000000001000 RSI: ffffa06e5d7dc000 RDI: 0000000000000003
RBP: ffffa06e5d7ddec0 R08: ffffa06e6120a800 R09: ffffa06e7a119900
R10: 0000000000002310 R11: ffffa06e5d7dcec0 R12: ffffe4360575f740
R13: ffffe43600000000 R14: 0000000000000002 R15: 0000000000000002
FS: 0000000000000000(0000) GS:ffffa0755f700000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f147b76b0f8 CR3: 00000001615d4000 CR4: 00000000007506f0
PKRU: 55555554
Call Trace:
<IRQ>
? __warn+0x84/0x130
? skb_try_coalesce+0x504/0x590
? report_bug+0x18a/0x1a0
? handle_bug+0x53/0x90
? exc_invalid_op+0x14/0x70
? asm_exc_invalid_op+0x16/0x20
? skb_try_coalesce+0x504/0x590
inet_frag_reasm_finish+0x11f/0x2e0
ip_defrag+0x37a/0x900
ip_local_deliver+0x51/0x120
ip_sublist_rcv_finish+0x64/0x70
ip_sublist_rcv+0x179/0x210
ip_list_rcv+0xf9/0x130
How to reproduce:
<Node A>
ip link set $interface1 xdp obj xdp_pass.o
ip link set $interface1 mtu 9000 up
ip a a 10.0.0.1/24 dev $interface1
<Node B>
ip link set $interfac2 mtu 9000 up
ip a a 10.0.0.2/24 dev $interface2
ping 10.0.0.1 -s 65000
Following ping.py patch adds xdp-mb-pass case. so ping.py is going to be
able to reproduce this issue.
Security readout for executives and security teams
Plain-English summary
A Linux bnxt network-driver accounting error can mishandle certain large packets when multi-buffer XDP passes traffic into the normal networking stack. The documented result is a kernel warning during packet reassembly; the CVSS assessment indicates potentially serious availability impact. Confidentiality and data integrity are not identified as affected.
Executive priority
Prioritize affected network-facing infrastructure, especially systems dependent on continuous packet processing. Treat remediation as high priority where bnxt multi-buffer XDP is enabled. Systems without that configuration are less likely exposed, but kernel and driver inventory should confirm this rather than relying on assumptions.
Technical view
With multi-buffer XDP enabled and XDP_PASS returned, bnxt_xdp_build_skb() supplied an incorrect truesize after napi_build_skb() cleared shared metadata. The fix preserves the fragment count before conversion and uses it when updating skb shared information. The demonstrated fault reaches skb_try_coalesce() during IP fragment reassembly.
Likely exposure
Exposure appears limited to Linux systems using the bnxt driver with multi-buffer XDP and an XDP_PASS path. Large or fragmented packets are implicated. The bundle lists affected kernel releases including 5.19, 6.12.20, 6.13.8, and 6.14, but downstream distribution status requires vendor confirmation.
Exploitation context
The CVSS 3.1 rating is 7.5 with network reachability, low complexity, no privileges, and no user interaction. However, the supplied evidence documents reproduction and a kernel warning, not malicious exploitation. CISA KEV status is false, and no cited source establishes active exploitation.
Researcher notes
The source bundle supports an availability-focused flaw caused by incorrect skb truesize accounting. It does not establish code execution, information disclosure, privilege escalation, or active exploitation. Exact introduction and fixed-version boundaries are not clearly mapped in the supplied version data; assess distribution backports against the three referenced stable commits.
Mitigation direction
Update to a vendor-supported kernel containing the applicable stable fix.
Confirm the corrected package or backport with the operating-system vendor.
If patching is delayed, avoid multi-buffer XDP_PASS on bnxt where operationally acceptable.
Monitor kernel logs for skb_try_coalesce warnings and related network disruption.
Validation and detection
Inventory hosts using the bnxt driver and record their exact kernel builds.
Identify bnxt interfaces running XDP programs that can return XDP_PASS.
Verify vendor advisories or package changelogs include the relevant stable fix.
Confirm kernel logs remain free of the documented warning after remediation.
Use safe staging tests for large and fragmented traffic; avoid production disruption.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cve · low confidence lookup
CVE-2025-21961 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.