CVE-2025-21829
This vulnerability involves the RDMA/rxe driver in the Linux kernel, where a warning can cause improper cleanup of RDMA resources when many are allocated. The issue can lead to resource exhaustion or system instability. A patch has been released to fix the timeout handling.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Linux kernel, all versions that include the RDMA/rxe driver before the patch for CVE-2025-21829.
Real-world impact
An attacker could cause the system to run out of RDMA resources, potentially leading to denial of service or system crashes.
Why this severity
The CVSS score of 9.8 reflects a critical vulnerability that requires no authentication, no user interaction, and can fully compromise confidentiality, integrity, and availability.
What to do about it
- 01Upgrade to a Linux kernel version that includes the fix for CVE-2025-21829.
- 02Reboot the system to load the updated kernel.
NVD-referenced vendor advisory
Timeline
- Mar 6, 2025 · Mar 6, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 7d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.