{"id":"DEBIAN-CVE-2025-21921","details":"In the Linux kernel, the following vulnerability has been resolved:  net: ethtool: netlink: Allow NULL nlattrs when getting a phy_device  ethnl_req_get_phydev() is used to lookup a phy_device, in the case an ethtool netlink command targets a specific phydev within a netdev's topology.  It takes as a parameter a const struct nlattr *header that's used for error handling :         if (!phydev) {                NL_SET_ERR_MSG_ATTR(extack, header,                                    \"no phy matching phyindex\");                return ERR_PTR(-ENODEV);        }  In the notify path after a -\u003eset operation however, there's no request attributes available.  The typical callsite for the above function looks like:  \tphydev = ethnl_req_get_phydev(req_base, tb[ETHTOOL_A_XXX_HEADER], \t\t\t\t      info-\u003eextack);  So, when tb is NULL (such as in the ethnl notify path), we have a nice crash.  It turns out that there's only the PLCA command that is in that case, as the other phydev-specific commands don't have a notification.  This commit fixes the crash by passing the cmd index and the nlattr array separately, allowing NULL-checking it directly inside the helper.","modified":"2026-09-01T20:05:43.000883920Z","published":"2025-04-01T16:15:22.790Z","upstream":["CVE-2025-21921"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-21921"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.19-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21921.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.19-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21921.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}