cbcvebase.
CVE-2025-21680
published 2025-01-31

CVE-2025-21680: In the Linux kernel, the following vulnerability has been resolved: pktgen: Avoid out-of-bounds access in get_imix_entries Passing a sufficient amount of imix…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.22%
12.5th percentile
In the Linux kernel, the following vulnerability has been resolved: pktgen: Avoid out-of-bounds access in get_imix_entries Passing a sufficient amount of imix entries leads to invalid access to the pkt_dev->imix_entries array because of the incorrect boundary check. UBSAN: array-index-out-of-bounds in net/core/pktgen.c:874:24 index 20 is out of range for type 'imix_pkt [20]' CPU: 2 PID: 1210 Comm: bash Not tainted 6.10.0-rc1 #121 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) Call Trace: dump_stack_lvl lib/dump_stack.c:117 __ubsan_handle_out_of_bounds lib/ubsan.c:429 get_imix_entries net/core/pktgen.c:874 pktgen_if_write net/core/pktgen.c:1063 pde_write fs/proc/inode.c:334 proc_reg_write fs/proc/inode.c:346 vfs_write fs/read_write.c:593 ksys_write fs/read_write.c:644 do_syscall_64 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:130 Found by Linux Verification Center (linuxtesting.org) with SVACE. [ fp: allow to fill the array completely; minor changelog cleanup ]

Affected

22 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
fig2dev_projectfig2dev>= 0 < 1:3.2.6a-6ubuntu1.1+esm11:3.2.6a-6ubuntu1.1+esm1
fig2dev_projectfig2dev>= 0 < 1:3.2.7a-7ubuntu0.1+esm11:3.2.7a-7ubuntu0.1+esm1
fig2dev_projectfig2dev>= 0 < 1:3.2.8b-1ubuntu0.1~esm11:3.2.8b-1ubuntu0.1~esm1
fig2dev_projectfig2dev>= 0 < 1:3.2.9-3ubuntu0.1~esm11:3.2.9-3ubuntu0.1~esm1
linuxlinux
linuxlinux>= 52a62f8603f97e720882c8f5aff2767ac6a11d5f < 3450092cc2d1c311c5ea92a2486daa2a33520ea53450092cc2d1c311c5ea92a2486daa2a33520ea5
linuxlinux>= 52a62f8603f97e720882c8f5aff2767ac6a11d5f < e5d24a7074dcd0c7e76b7e7e4efbbe7418d62486e5d24a7074dcd0c7e76b7e7e4efbbe7418d62486
linuxlinux>= 52a62f8603f97e720882c8f5aff2767ac6a11d5f < 7cde21f52042aa2e29a654458166b873d2ae66b37cde21f52042aa2e29a654458166b873d2ae66b3
linuxlinux>= 52a62f8603f97e720882c8f5aff2767ac6a11d5f < 1a9b65c672ca9dc4ba52ca2fd54329db9580ce291a9b65c672ca9dc4ba52ca2fd54329db9580ce29
linuxlinux>= 52a62f8603f97e720882c8f5aff2767ac6a11d5f < 76201b5979768500bca362871db66d77cb4c225e76201b5979768500bca362871db66d77cb4c225e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1
linuxlinux_kernel>= 0 < 6.12.11-16.12.11-1
linuxlinux_kernel>= 0 < 6.12.11-16.12.11-1
linuxlinux_kernel>= 0 < 5.15.0-135.1465.15.0-135.146
linuxlinux_kernel>= 0 < 6.8.0-62.656.8.0-62.65
linuxlinux_kernel>= 5.15 < 5.15.1775.15.177
linuxlinux_kernel>= 5.16 < 6.1.1276.1.127
linuxlinux_kernel>= 6.2 < 6.6.746.6.74
linuxlinux_kernel>= 6.7 < 6.12.116.12.11

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.