Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-71092

24
FAUCET Score

CVE-2025-71092 describes an out-of-bounds write vulnerability in the Linux kernel's RDMA bnxt_re driver. Specifically, a misplacement of new hardware counters in the bnxt_re_copy_err_stats() function led to an attempt to write beyond allocated memory. This issue affects systems utilizing the bnxt_re driver, particularly those with chip_gen_p5_p7 devices, though the fix addresses generic hardware counter inclusion. The vulnerability's severity is currently unrated by CVSS, but its nature as an out-of-bounds write suggests potential for system instability or denial of service, and possibly arbitrary code execution depending on context. The attack vector would likely involve specific RDMA operations. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE. The vulnerability is considered inactive on the Hot List.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.18.1, < 6.18.4CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.18CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.18:-:*:*:*:*:*:*
6.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
6.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
6.19CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.11%
Probability of exploitation in next 30 days
EPSS Percentile
1.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0011 is in the 7th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2025-71092

kernel: RDMA/bnxt_re: Fix OOB write in bnxt_re_copy_err_stats()

Jan 13, 2026

References

git.kernel.org / stable/c/369a161c48723f60f06f3510b82ea7d96d0499ab
Patch
git.kernel.org / stable/c/9b68a1cc966bc947d00e4c0df7722d118125aa37
Patch