cbcvebase.
CVE-2025-21704
published 2025-02-22

CVE-2025-21704: In the Linux kernel, the following vulnerability has been resolved: usb: cdc-acm: Check control transfer buffer size before access If the first fragment is…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.34%
26.9th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: cdc-acm: Check control transfer buffer size before access If the first fragment is shorter than struct usb_cdc_notification, we can't calculate an expected_size. Log an error and discard the notification instead of reading lengths from memory outside the received data, which can lead to memory corruption when the expected_size decreases between fragments, causing `expected_size - acm->nb_index` to wrap. This issue has been present since the beginning of git history; however, it only leads to memory corruption since commit ea2583529cd1 ("cdc-acm: reassemble fragmented notifications"). A mitigating factor is that acm_ctrl_irq() can only execute after userspace has opened /dev/ttyACM*; but if ModemManager is running, ModemManager will do that automatically depending on the USB device's vendor/product IDs and its other interfaces.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
googlechrome_chrome
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < a4e1ae5c0533964170197e4fb4f33bc8c1db5cd2a4e1ae5c0533964170197e4fb4f33bc8c1db5cd2
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 90dd2f1b7342b9a671a5ea4160f408037b92b11890dd2f1b7342b9a671a5ea4160f408037b92b118
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 871619c2b78fdfe05afb4e8ba548678687beb812871619c2b78fdfe05afb4e8ba548678687beb812
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 7828e9363ac4d23b02419bf2a45b9f1d9fb356467828e9363ac4d23b02419bf2a45b9f1d9fb35646
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 6abb510251e75f875797d8983a830e6731fa281c6abb510251e75f875797d8983a830e6731fa281c
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < f64079bef6a8a7823358c3f352ea29a617844636f64079bef6a8a7823358c3f352ea29a617844636
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 383d516a0ebc8641372b521c8cb717f0f1834831383d516a0ebc8641372b521c8cb717f0f1834831
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < e563b01208f4d1f609bcab13333b6c0e24ce6a01e563b01208f4d1f609bcab13333b6c0e24ce6a01
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-78.786.8.0-78.78
linuxlinux_kernel>= 0 < 4.4.0-278.3124.4.0-278.312
linuxlinux_kernel>= 0 < 4.15.0-247.2594.15.0-247.259
linuxlinux_kernel>= 2.6.13 < 5.4.2915.4.291
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_msrc5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.