CVE-2025-21687
10.02.2025, 16:15
In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write syscalls count and offset are passed from user space and not checked, only offset is capped to 40 bits, which can be used to read/write out of bounds of the device.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 4.1 ≤ 𝑥 < 5.4.290 |
linux | linux_kernel | 5.5 ≤ 𝑥 < 5.10.234 |
linux | linux_kernel | 5.11 ≤ 𝑥 < 5.15.178 |
linux | linux_kernel | 5.16 ≤ 𝑥 < 6.1.128 |
linux | linux_kernel | 6.2 ≤ 𝑥 < 6.6.75 |
linux | linux_kernel | 6.7 ≤ 𝑥 < 6.12.12 |
linux | linux_kernel | 6.13 |
linux | linux_kernel | 6.13:rc1 |
linux | linux_kernel | 6.13:rc2 |
linux | linux_kernel | 6.13:rc3 |
linux | linux_kernel | 6.13:rc4 |
linux | linux_kernel | 6.13:rc5 |
linux | linux_kernel | 6.13:rc6 |
linux | linux_kernel | 6.13:rc7 |
𝑥
= Vulnerable software versions

Debian Releases
Common Weakness Enumeration
Vulnerability Media Exposure
References