CVE-2025-21998 | Linux Kernel up to 6.12.20/6.13.8 Efivars Service null pointer dereference (Nessus ID 241070 / WID-SEC-2025-0698)
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.12.20/6.13.8. Affected is an unknown function of the component Efivars Service. This manipulation causes null pointer dereference.
This vulnerability is registered as CVE-2025-21998. The attack requires access to the local network. No exploit is available.
It is advisable to upgrade the affected component.