CVE-2025-1651
published 2025-03-13CVE-2025-1651: A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this…
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.22%
12.9th percentile
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | advance_steel | >= 2022 < 2022.1.6 | 2022.1.6 |
| autodesk | advance_steel | >= 2023 < 2023.1.7 | 2023.1.7 |
| autodesk | advance_steel | >= 2024 < 2024.1.7 | 2024.1.7 |
| autodesk | advance_steel | >= 2025 < 2025.1.2 | 2025.1.2 |
| autodesk | autocad | >= 2022 < 2022.1.6 | 2022.1.6 |
| autodesk | autocad | >= 2023 < 2023.1.7 | 2023.1.7 |
| autodesk | autocad | >= 2024 < 2024.1.7 | 2024.1.7 |
| autodesk | autocad | >= 2025 < 2025.1.2 | 2025.1.2 |
| autodesk | autocad_architecture | >= 2022 < 2022.1.6 | 2022.1.6 |
| autodesk | autocad_architecture | >= 2023 < 2023.1.7 | 2023.1.7 |
| autodesk | autocad_architecture | >= 2024 < 2024.1.7 | 2024.1.7 |
| autodesk | autocad_architecture | >= 2025 < 2025.1.2 | 2025.1.2 |
| autodesk | autocad_electrical | >= 2022 < 2022.1.6 | 2022.1.6 |
| autodesk | autocad_electrical | >= 2023 < 2023.1.7 | 2023.1.7 |
| autodesk | autocad_electrical | >= 2024 < 2024.1.7 | 2024.1.7 |
| autodesk | autocad_electrical | >= 2025 < 2025.1.2 | 2025.1.2 |
| autodesk | autocad_map_3d | >= 2022 < 2022.1.6 | 2022.1.6 |
| autodesk | autocad_map_3d | >= 2023 < 2023.1.7 | 2023.1.7 |
| autodesk | autocad_map_3d | >= 2024 < 2024.1.7 | 2024.1.7 |
| autodesk | autocad_map_3d | >= 2025 < 2025.1.2 | 2025.1.2 |
| autodesk | autocad_mechanical | >= 2022 < 2022.1.6 | 2022.1.6 |
| autodesk | autocad_mechanical | >= 2023 < 2023.1.7 | 2023.1.7 |
| autodesk | autocad_mechanical | >= 2024 < 2024.1.7 | 2024.1.7 |
| autodesk | autocad_mechanical | >= 2025 < 2025.1.2 | 2025.1.2 |
| autodesk | autocad_mep | >= 2022 < 2022.1.6 | 2022.1.6 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv5.5MEDIUM
vendor_msrc7.1HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
cpuset: fix warning when disabling remote partition
osv·2026-01-14·CVSS 5.5
CVE-2025-71142 cpuset: fix warning when disabling remote partition
cpuset: fix warning when disabling remote partition
In the Linux kernel, the following vulnerability has been resolved:
cpuset: fix warning when disabling remote partition
A warning was triggered as follows:
WARNING: kernel/cgroup/cpuset.c:1651 at remote_partition_disable+0xf7/0x110
RIP: 0010:remote_partition_disable+0xf7/0x110
RSP: 0018:ffffc90001947d88 EFLAGS: 00000206
RAX: 0000000000007fff RBX: ffff888103b6e000 RCX: 0000000000006f40
RDX: 0000000000006f00 RSI: ffffc90001947da8 RDI: ffff888103b6e000
RBP: ffff888103b6e000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000001 R11: ffff88810b2e2728 R12: ffffc90001947da8
R13: 0000000000000000 R14: ffffc90001947da8 R15: ffff8881081f1c00
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f55c8bbe0b2 CR3: 000000010b14c000
GHSA
GHSA-hgvp-m8qf-mg69: A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability
ghsa_unreviewed·2025-03-13
CVE-2025-1651 [HIGH] CWE-122 GHSA-hgvp-m8qf-mg69: A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability
A maliciously crafted MODEL file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
Red Hat
kernel: cpuset: fix warning when disabling remote partition
vendor_redhat·2026-01-14·CVSS 5.5
CVE-2025-71142 [MEDIUM] CWE-480 kernel: cpuset: fix warning when disabling remote partition
kernel: cpuset: fix warning when disabling remote partition
In the Linux kernel, the following vulnerability has been resolved:
cpuset: fix warning when disabling remote partition
A warning was triggered as follows:
WARNING: kernel/cgroup/cpuset.c:1651 at remote_partition_disable+0xf7/0x110
RIP: 0010:remote_partition_disable+0xf7/0x110
RSP: 0018:ffffc90001947d88 EFLAGS: 00000206
RAX: 0000000000007fff RBX: ffff888103b6e000 RCX: 0000000000006f40
RDX: 0000000000006f00 RSI: ffffc90001947da8 RDI: ffff888103b6e000
RBP: ffff888103b6e000 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000001 R11: ffff88810b2e2728 R12: ffffc90001947da8
R13: 0000000000000000 R14: ffffc90001947da8 R15: ffff8881081f1c00
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f55c8bbe0b2 CR3: 000000010b1
Microsoft
A memory leak flaw was found in the Linux kernel in acrn_dev_ioctl in the drivers/virt/acrn/hsm.c function in how the ACRN Device Model emulates virtual NICs in VM. This flaw allows a local privileged
vendor_msrc·2022-07-12·CVSS 7.1
CVE-2022-1651 [HIGH] CWE-401 A memory leak flaw was found in the Linux kernel in acrn_dev_ioctl in the drivers/virt/acrn/hsm.c function in how the ACRN Device Model emulates virtual NICs in VM. This flaw allows a local privileged
A memory leak flaw was found in the Linux kernel in acrn_dev_ioctl in the drivers/virt/acrn/hsm.c function in how the ACRN Device Model emulates virtual NICs in VM. This flaw allows a local privileged attacker to leak unauthorized kernel information causing a denial of service.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more i
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-03-13
Published