CVE-2025-21650Out-of-bounds Write in Linux

Severity
7.8HIGHNVD
OSV7.1OSV6.2OSV5.5
EPSS
0.0%
top 92.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 19
Latest updateMay 29

Description

In the Linux kernel, the following vulnerability has been resolved: net: hns3: fixed hclge_fetch_pf_reg accesses bar space out of bounds issue The TQP BAR space is divided into two segments. TQPs 0-1023 and TQPs 1024-1279 are in different BAR space addresses. However, hclge_fetch_pf_reg does not distinguish the tqp space information when reading the tqp space information. When the number of TQPs is greater than 1024, access bar space overwriting occurs. The problem of different segments has be

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

NVDlinux/linux_kernel6.4.166.5+2
Debianlinux/linux_kernel< 6.12.10-1+1
Ubuntulinux/linux_kernel< 6.8.0-60.63
CVEListV5linux/linux939ccd107ffcade20c9c7055a2e7ae0fd724fb720575baa733fc4219f230aef22d5bc35d922f1e9a+4
debiandebian/linux< linux 6.12.10-1 (forky)

Patches

🔴Vulnerability Details

18
OSV
linux-oracle-6.8 vulnerabilities2025-05-29
OSV
linux-hwe-6.8 vulnerabilities2025-05-28
OSV
linux-raspi vulnerabilities2025-05-26
OSV
linux-azure-nvidia vulnerabilities2025-05-20
OSV
linux-raspi-realtime vulnerabilities2025-05-20

📋Vendor Advisories

18
Ubuntu
Linux kernel (Oracle) vulnerabilities2025-05-29
Ubuntu
Linux kernel (HWE) vulnerabilities2025-05-28
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2025-05-26
Ubuntu
Linux kernel vulnerabilities2025-05-20
Ubuntu
Linux kernel (Azure, N-Series) vulnerabilities2025-05-20
CVE-2025-21650 — Out-of-bounds Write in Linux | cvebase