cbcvebase.
CVE-2025-21687
published 2025-02-10

CVE-2025-21687: In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write syscalls count and offset are passed from…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.23%
13.8th percentile
In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write syscalls count and offset are passed from user space and not checked, only offset is capped to 40 bits, which can be used to read/write out of bounds of the device.

Affected

37 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
debianlinux-6.1< linux 6.1.128-1 (bookworm)linux 6.1.128-1 (bookworm)
linuxlinux
linuxlinux>= 6e3f264560099869f68830cb14b3b3e71e5ac76a < f21636f24b6786c8b13f1af4319fa75ffcf17f38f21636f24b6786c8b13f1af4319fa75ffcf17f38
linuxlinux>= 6e3f264560099869f68830cb14b3b3e71e5ac76a < 9377cdc118cf327248f1a9dde7b87de067681dc99377cdc118cf327248f1a9dde7b87de067681dc9
linuxlinux>= 6e3f264560099869f68830cb14b3b3e71e5ac76a < d19a8650fd3d7aed8d1af1d9a77f979a8430eba1d19a8650fd3d7aed8d1af1d9a77f979a8430eba1
linuxlinux>= 6e3f264560099869f68830cb14b3b3e71e5ac76a < ed81d82bb6e9df3a137f2c343ed689e6c68268efed81d82bb6e9df3a137f2c343ed689e6c68268ef
linuxlinux>= 6e3f264560099869f68830cb14b3b3e71e5ac76a < 92340e6c5122d823ad064984ef7513eba920404892340e6c5122d823ad064984ef7513eba9204048
linuxlinux>= 6e3f264560099869f68830cb14b3b3e71e5ac76a < f65ce06387f8c1fb54bd59e18a8428248ec68eaff65ce06387f8c1fb54bd59e18a8428248ec68eaf
linuxlinux>= 6e3f264560099869f68830cb14b3b3e71e5ac76a < 6bcb8a5b70b80143db9bf12dfa7d53636f824d536bcb8a5b70b80143db9bf12dfa7d53636f824d53
linuxlinux>= 6e3f264560099869f68830cb14b3b3e71e5ac76a < 1485932496a1b025235af8aa1e21988d6b7ccd541485932496a1b025235af8aa1e21988d6b7ccd54
linuxlinux>= 6e3f264560099869f68830cb14b3b3e71e5ac76a < c981c32c38af80737a2fedc16e270546d139ccddc981c32c38af80737a2fedc16e270546d139ccdd
linuxlinux>= 6e3f264560099869f68830cb14b3b3e71e5ac76a < a20fcaa230f7472456d12cf761ed13938e320ac3a20fcaa230f7472456d12cf761ed13938e320ac3
linuxlinux>= 6e3f264560099869f68830cb14b3b3e71e5ac76a < 665cfd1083866f87301bbd232cb8ba48dcf4acce665cfd1083866f87301bbd232cb8ba48dcf4acce
linuxlinux>= 6e3f264560099869f68830cb14b3b3e71e5ac76a < ce9ff21ea89d191e477a02ad7eabf4f996b80a69ce9ff21ea89d191e477a02ad7eabf4f996b80a69
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.234-15.10.234-1
linuxlinux_kernel>= 0 < 6.1.128-16.1.128-1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.