# CVE-2025-21802

## Summary

- **CVE ID:** CVE-2025-21802
- **Severity:** MEDIUM
- **CVSS Score:** 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** N/A
- **Published:** Feb 27, 2025
- **Last Modified:** Sep 8, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

net: hns3: fix oops when unload drivers paralleling

When unload hclge driver, it tries to disable sriov first for each
ae_dev node from hnae3_ae_dev_list. If user unloads hns3 driver at
the time, because it removes all the ae_dev nodes, and it may cause
oops.

But we can't simply use hnae3_common_lock for this. Because in the
process flow of pci_disable_sriov(), it will trigger the remove flow
of VF, which will also take hnae3_common_lock.

To fixes it, introduce a new mutex to protect the unload process.

## Affected Products

- Linux — Linux (d36b15e3e7b5937cb1f6ac590a85facc3a320642)
- Linux — Linux (0dd8a25f355b4df2d41c08df1716340854c7d4c5)
- Linux — Linux (b06ad258e01389ca3ff13bc180f3fcd6a608f1cd)
- Linux — Linux (c4b64011e458aa2b246cd4e42012cfd83d2d9a5c)
- Linux — Linux (9b5a29f0acefa3eb1dbe2fa302b393eeff64d933)
- Linux — Linux (5.15)
- Linux — Linux (0)
- Linux — Linux (5.10.235)
- Linux — Linux (5.15.179)
- Linux — Linux (6.1.129)
- Linux — Linux (6.6.76)
- Linux — Linux (6.12.13)
- Linux — Linux (6.13.2)
- Linux — Linux (6.14)
- Linux — Linux (5.10.76)
- Linux — Linux (4.19.214)
- Linux — Linux (5.4.156)
- Linux — Linux (5.14.15)

## References

- [CNA](https://git.kernel.org/stable/c/622d92a67656e5c4d2d6ccac02d688ed995418c6)
- [CNA](https://git.kernel.org/stable/c/8c640dd3d900cc8988a39c007591f1deee776df4)
- [CNA](https://git.kernel.org/stable/c/e876522659012ef2e73834a0b9f1cbe3f74d5fad)
- [CNA](https://git.kernel.org/stable/c/b5a8bc47aa0a4aa8bca5466dfa2d12dbb5b3cd0c)
- [CNA](https://git.kernel.org/stable/c/82736bb83fb0221319c85c2e9917d0189cd84e1e)
- [CNA](https://git.kernel.org/stable/c/cafe9a27e22736d4a01b3933e36225f9857c7988)
- [CNA](https://git.kernel.org/stable/c/92e5995773774a3e70257e9c95ea03518268bea5)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-019113.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 10.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._