cbcvebase.
CVE-2025-21905
published 2025-04-01

CVE-2025-21905: In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: limit printed string from FW file There's no guarantee here that the file is…

PriorityP430high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.21%
10.8th percentile
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: limit printed string from FW file There's no guarantee here that the file is always with a NUL-termination, so reading the string may read beyond the end of the TLV. If that's the last TLV in the file, it can perhaps even read beyond the end of the file buffer. Fix that by limiting the print format to the size of the buffer we have.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= aee1b6385e29e472ae5592b9652b750a29bf702e < 38f0d398b6d7640d223db69df022c4a232f2477438f0d398b6d7640d223db69df022c4a232f24774
linuxlinux>= aee1b6385e29e472ae5592b9652b750a29bf702e < c0e626f2b2390472afac52dfe72b29daf9ed8e1dc0e626f2b2390472afac52dfe72b29daf9ed8e1d
linuxlinux>= aee1b6385e29e472ae5592b9652b750a29bf702e < 47616b82f2d42ea2060334746fed9a2988d845c947616b82f2d42ea2060334746fed9a2988d845c9
linuxlinux>= aee1b6385e29e472ae5592b9652b750a29bf702e < 88ed69f924638c7503644e1f8eed1e976f3ffa7a88ed69f924638c7503644e1f8eed1e976f3ffa7a
linuxlinux>= aee1b6385e29e472ae5592b9652b750a29bf702e < b02f8d5a71c8571ccf77f285737c566db73ef5e5b02f8d5a71c8571ccf77f285737c566db73ef5e5
linuxlinux>= aee1b6385e29e472ae5592b9652b750a29bf702e < f265e6031d0bc4fc40c4619cb42466722b46eaa9f265e6031d0bc4fc40c4619cb42466722b46eaa9
linuxlinux>= aee1b6385e29e472ae5592b9652b750a29bf702e < 59cdda202829d1d6a095d233386870a59aff986f59cdda202829d1d6a095d233386870a59aff986f
linuxlinux>= aee1b6385e29e472ae5592b9652b750a29bf702e < e0dc2c1bef722cbf16ae557690861e5f91208129e0dc2c1bef722cbf16ae557690861e5f91208129
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 6.12.19-16.12.19-1
linuxlinux_kernel>= 0 < 5.4.0-216.2365.4.0-216.236
linuxlinux_kernel>= 0 < 5.15.0-140.1505.15.0-140.150
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 5.11 < 5.15.1795.15.179
linuxlinux_kernel>= 5.16 < 6.1.1316.1.131
linuxlinux_kernel>= 5.2 < 5.4.2915.4.291
linuxlinux_kernel>= 5.5 < 5.10.2355.10.235
linuxlinux_kernel>= 6.13 < 6.13.76.13.7
linuxlinux_kernel>= 6.2 < 6.6.836.6.83

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.