CVE-2025-71092 describes an out-of-bounds write vulnerability in the Linux kernel's RDMA bnxt_re driver. Specifically, a misplacement of new hardware counters in the bnxt_re_copy_err_stats() function led to an attempt to write beyond allocated memory. This issue affects systems utilizing the bnxt_re driver, particularly those with chip_gen_p5_p7 devices, though the fix addresses generic hardware counter inclusion. The vulnerability's severity is currently unrated by CVSS, but its nature as an out-of-bounds write suggests potential for system instability or denial of service, and possibly arbitrary code execution depending on context. The attack vector would likely involve specific RDMA operations. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE. The vulnerability is considered inactive on the Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.18.1, < 6.18.4CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.18CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.18:-:*:*:*:*:*:* | ||
6.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:* | ||
6.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:* | ||
6.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.