Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-21732

15
FAUCET Score

CVE-2025-21732 describes a race condition in the Linux kernel's RDMA/mlx5 driver, specifically affecting the handling of On-Demand Paging (ODP) Memory Regions (MRs). This vulnerability can lead to a Completion Queue Entry (CQE) with an error on the UMR QP, causing the UMR QP to enter an error state. The issue arises when an ODP MR's lkey is freed from hardware while another task concurrently attempts to invalidate a range for the same freed lkey. Rated with a CVSS score of 4.7 (MEDIUM), the vulnerability has a local attack vector and high attack complexity, requiring low privileges and no user interaction. The primary impact is a high availability loss, as the UMR QP can become unusable. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating a low level of public attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 5.13, < 6.12.14CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.13, < 6.13.3CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.7MEDIUM

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.0
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.14%
Probability of exploitation in next 30 days
EPSS Percentile
3.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0014 is in the 27th percentile among its peer group of 1,297 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel-0:6.12.0-124.8.1.el10_1
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: kernel-rt
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: kernel-rt

Vendor Advisories (2)

redhatCVE-2025-21732Moderate

kernel: RDMA/mlx5: Fix a race for an ODP MR which leads to CQE with error

Feb 27, 2025
microsoft2025-Feb/CVE-2025-21732Moderate

RDMA/mlx5: Fix a race for an ODP MR which leads to CQE with error

Feb 11, 2025

References

git.kernel.org / stable/c/5297f5ddffef47b94172ab0d3d62270002a3dcc1
Patch
git.kernel.org / stable/c/abb604a1a9c87255c7a6f3b784410a9707baf467
Patch
git.kernel.org / stable/c/b13d32786acabf70a7b04ed24b7468fc3c82977c
Patch