CVE-2025-21680

Published Jan 31, 2025

Last updated 5 months ago

Overview

Description
In the Linux kernel, the following vulnerability has been resolved: pktgen: Avoid out-of-bounds access in get_imix_entries Passing a sufficient amount of imix entries leads to invalid access to the pkt_dev->imix_entries array because of the incorrect boundary check. UBSAN: array-index-out-of-bounds in net/core/pktgen.c:874:24 index 20 is out of range for type 'imix_pkt [20]' CPU: 2 PID: 1210 Comm: bash Not tainted 6.10.0-rc1 #121 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) Call Trace: <TASK> dump_stack_lvl lib/dump_stack.c:117 __ubsan_handle_out_of_bounds lib/ubsan.c:429 get_imix_entries net/core/pktgen.c:874 pktgen_if_write net/core/pktgen.c:1063 pde_write fs/proc/inode.c:334 proc_reg_write fs/proc/inode.c:346 vfs_write fs/read_write.c:593 ksys_write fs/read_write.c:644 do_syscall_64 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:130 Found by Linux Verification Center (linuxtesting.org) with SVACE. [ fp: allow to fill the array completely; minor changelog cleanup ]
Source
416baaa9-dc9f-4396-8d5f-8c081fb06d67
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-129

Social media

Hype score
Not currently trending
  1. 🚨 CVE-2025-21680 (8.5 CVSS) in Linux pktgen allows kernel memory corruption! Patch SLE 15 SP6 systems NOW: zypper in -t patch SUSE-2025-1957=1 Details: 👉 https://t.co/KU6yj1mLVt #LinuxSecurity #SysAdmi https://t.co/a3ZJDZNHDX

    @Cezar_H_Linux

    17 Jun 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 Critical #LinuxKernel patches released! CVE-2025-21680, CVE-2024-58013, and CVE-2024-57996 (CVSS 7.0-8.5) patched in SUSE’s latest update. Don’t delay—secure your systems today! Read more: 📷 https://t.co/nh4d6o4Mo9 #CyberSecuirty https:

    @Cezar_H_Linux

    16 Jun 2025

    52 Impressions

    1 Retweet

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  3. CVE-2025-21680 (8.5 CVSS) lets attackers escalate privileges via Linux Kernel’s pktgen. SUSE’s Live Patch 6 for SLE 15 SP6 fixes this + 2 other critical flaws. Read more: 👉 https://t.co/Hzs5rElLgY #LinuxSecurity #DevOps #SysAdmin https://t.co/I1W11vwC55

    @Cezar_H_Linux

    15 Jun 2025

    37 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 1/3 🚨 Breaking: #SUSE patches 4 high-severity Linux Kernel vulnerabilities (CVE-2025-21680, CVE-2024-57996) in SLE 15 SP6. CVSS scores up to 8.5! Read more: 👉https://t.co/2cbKTboLGN #LinuxSecurity #DevOps https://t.co/WzP0SeM11Y

    @Cezar_H_Linux

    14 Jun 2025

    51 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 Breaking: #SUSE patches 4 high-risk Linux Kernel flaws (CVE-2024-49855, CVE-2025-21680). Live Patch 4 for SLE 15 SP6 is out—update ASAP! Read more: 👉https://t.co/bwLrXHEclA #Linux #Infosec https://t.co/6lTpikhUH8

    @Cezar_H_Linux

    14 Jun 2025

    53 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 openSUSE Leap 15.6 kernel update fixes: CVE-2025-21680 (pktgen RCE) CVE-2024-58013 (Bluetooth MGMT exploit) 2 other high-risk CVEs zypper patch ASAP if using NBD/BLE. Read more: 👉 https://t.co/XTaBUCfXk6 #InfoSec #SysAdmin https://t.c

    @Cezar_H_Linux

    13 Jun 2025

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2025-21680 In the Linux kernel, the following vulnerability has been resolved: pktgen https://t.co/jBslIDuoE7

    @VulmonFeeds

    31 Jan 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2025-21680 In the Linux kernel, the following vulnerability has been resolved: pktgen: Avoid out-of-bounds access in get_imix_entries Passing a sufficient amount of imix entri… https://t.co/SAi8l02oRC

    @CVEnew

    31 Jan 2025

    387 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations