CVE-2025-21732 describes a race condition in the Linux kernel's RDMA/mlx5 driver, specifically affecting the handling of On-Demand Paging (ODP) Memory Regions (MRs). This vulnerability can lead to a Completion Queue Entry (CQE) with an error on the UMR QP, causing the UMR QP to enter an error state. The issue arises when an ODP MR's lkey is freed from hardware while another task concurrently attempts to invalidate a range for the same freed lkey. Rated with a CVSS score of 4.7 (MEDIUM), the vulnerability has a local attack vector and high attack complexity, requiring low privileges and no user interaction. The primary impact is a high availability loss, as the UMR QP can become unusable. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.13, < 6.12.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.13, < 6.13.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.