cbcvebase.
CVE-2025-21785
published 2025-02-27

CVE-2025-21785: In the Linux kernel, the following vulnerability has been resolved: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array The loop that…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
18.8th percentile
In the Linux kernel, the following vulnerability has been resolved: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array The loop that detects/populates cache information already has a bounds check on the array size but does not account for cache levels with separate data/instructions cache. Fix this by incrementing the index for any populated leaf (instead of any populated level).

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
debianlinux-6.1< linux 6.1.129-1 (bookworm)linux 6.1.129-1 (bookworm)
linuxlinux
linuxlinux>= 5d425c18653731af62831d30a4fa023d532657a9 < 4371ac7b494e933fffee2bd6265d18d73c4f05aa4371ac7b494e933fffee2bd6265d18d73c4f05aa
linuxlinux>= 5d425c18653731af62831d30a4fa023d532657a9 < e4fde33107351ec33f1a64188612fbc6ca659284e4fde33107351ec33f1a64188612fbc6ca659284
linuxlinux>= 5d425c18653731af62831d30a4fa023d532657a9 < 88a3e6afaf002250220793df99404977d343db1488a3e6afaf002250220793df99404977d343db14
linuxlinux>= 5d425c18653731af62831d30a4fa023d532657a9 < 4ff25f0b18d1d0174c105e4620428bcdc12138604ff25f0b18d1d0174c105e4620428bcdc1213860
linuxlinux>= 5d425c18653731af62831d30a4fa023d532657a9 < ab90894f33c15b14c1cee6959ab6c8dcb09127f8ab90894f33c15b14c1cee6959ab6c8dcb09127f8
linuxlinux>= 5d425c18653731af62831d30a4fa023d532657a9 < 715eb1af64779e1b1aa0a7b2ffb81414d9f708e5715eb1af64779e1b1aa0a7b2ffb81414d9f708e5
linuxlinux>= 5d425c18653731af62831d30a4fa023d532657a9 < 67b99a2b5811df4294c2ad50f9bff3b6a08bd61867b99a2b5811df4294c2ad50f9bff3b6a08bd618
linuxlinux>= 5d425c18653731af62831d30a4fa023d532657a9 < 875d742cf5327c93cba1f11e12b08d3cce7a88d2875d742cf5327c93cba1f11e12b08d3cce7a88d2
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.129-16.1.129-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 6.12.16-16.12.16-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-78.786.8.0-78.78
linuxlinux_kernel>= 4.0 < 6.1.1296.1.129
linuxlinux_kernel>= 6.13 < 6.13.46.13.4
linuxlinux_kernel>= 6.2 < 6.6.796.6.79
linuxlinux_kernel>= 6.7 < 6.12.166.12.16
msrcazl3_kernel_6.6.78.1-3_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.