We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-21680

pktgen: Avoid out-of-bounds access in get_imix_entries



Description

In the Linux kernel, the following vulnerability has been resolved: pktgen: Avoid out-of-bounds access in get_imix_entries Passing a sufficient amount of imix entries leads to invalid access to the pkt_dev->imix_entries array because of the incorrect boundary check. UBSAN: array-index-out-of-bounds in net/core/pktgen.c:874:24 index 20 is out of range for type 'imix_pkt [20]' CPU: 2 PID: 1210 Comm: bash Not tainted 6.10.0-rc1 #121 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) Call Trace: <TASK> dump_stack_lvl lib/dump_stack.c:117 __ubsan_handle_out_of_bounds lib/ubsan.c:429 get_imix_entries net/core/pktgen.c:874 pktgen_if_write net/core/pktgen.c:1063 pde_write fs/proc/inode.c:334 proc_reg_write fs/proc/inode.c:346 vfs_write fs/read_write.c:593 ksys_write fs/read_write.c:644 do_syscall_64 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe arch/x86/entry/entry_64.S:130 Found by Linux Verification Center (linuxtesting.org) with SVACE. [ fp: allow to fill the array completely; minor changelog cleanup ]

Reserved 2024-12-29 | Published 2025-01-31 | Updated 2025-01-31 | Assigner Linux

Product status

Default status
unaffected

52a62f8603f97e720882c8f5aff2767ac6a11d5f before 3450092cc2d1c311c5ea92a2486daa2a33520ea5
affected

52a62f8603f97e720882c8f5aff2767ac6a11d5f before e5d24a7074dcd0c7e76b7e7e4efbbe7418d62486
affected

52a62f8603f97e720882c8f5aff2767ac6a11d5f before 7cde21f52042aa2e29a654458166b873d2ae66b3
affected

52a62f8603f97e720882c8f5aff2767ac6a11d5f before 1a9b65c672ca9dc4ba52ca2fd54329db9580ce29
affected

52a62f8603f97e720882c8f5aff2767ac6a11d5f before 76201b5979768500bca362871db66d77cb4c225e
affected

Default status
affected

5.15
affected

Any version before 5.15
unaffected

5.15.177
unaffected

6.1.127
unaffected

6.6.74
unaffected

6.12.11
unaffected

6.13
unaffected

References

git.kernel.org/...c/3450092cc2d1c311c5ea92a2486daa2a33520ea5

git.kernel.org/...c/e5d24a7074dcd0c7e76b7e7e4efbbe7418d62486

git.kernel.org/...c/7cde21f52042aa2e29a654458166b873d2ae66b3

git.kernel.org/...c/1a9b65c672ca9dc4ba52ca2fd54329db9580ce29

git.kernel.org/...c/76201b5979768500bca362871db66d77cb4c225e

cve.org (CVE-2025-21680)

nvd.nist.gov (CVE-2025-21680)

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2025-21680

Support options

Helpdesk Chat, Email, Knowledgebase
Subscribe to our newsletter to learn more about our work.