# CVE-2025-21814

## Summary

- **CVE ID:** CVE-2025-21814
- **Severity:** MEDIUM
- **CVSS Score:** 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** N/A
- **Published:** Feb 27, 2025
- **Last Modified:** Sep 8, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ptp: Ensure info->enable callback is always set

The ioctl and sysfs handlers unconditionally call the ->enable callback.
Not all drivers implement that callback, leading to NULL dereferences.
Example of affected drivers: ptp_s390.c, ptp_vclock.c and ptp_mock.c.

Instead use a dummy callback if no better was specified by the driver.

## Affected Products

- Linux — Linux (d94ba80ebbea17f036cecb104398fbcd788aa742)
- Linux — Linux (3.0)
- Linux — Linux (0)
- Linux — Linux (5.4.291)
- Linux — Linux (5.10.235)
- Linux — Linux (5.15.179)
- Linux — Linux (6.1.129)
- Linux — Linux (6.6.78)
- Linux — Linux (6.12.14)
- Linux — Linux (6.13.3)
- Linux — Linux (6.14)

## References

- [CNA](https://git.kernel.org/stable/c/fdc1e72487781dd7705bcbe30878bee7d5d1f3e8)
- [CNA](https://git.kernel.org/stable/c/9df3a9284f39bfd51a9f72a6a165c79e2aa5066b)
- [CNA](https://git.kernel.org/stable/c/1334c64a5d1de6666e0c9f984db6745083df1eb4)
- [CNA](https://git.kernel.org/stable/c/5d1041c76de656f9f8d5a192218039a9acf9bd00)
- [CNA](https://git.kernel.org/stable/c/81846070cba17125a866e8023c01d3465b153339)
- [CNA](https://git.kernel.org/stable/c/8441aea46445252df5d2eed6deb6d5246fc24002)
- [CNA](https://git.kernel.org/stable/c/755caf4ee1c615ee5717862e427124370f46b1f3)
- [CNA](https://git.kernel.org/stable/c/fd53aa40e65f518453115b6f56183b0c201db26b)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-265688.html)
- [siemens-SADP](https://cert-portal.siemens.com/productcert/html/ssa-019113.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.25%
- **EPSS Percentile:** 16.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._