Linux Kernel Vulnerability with VFIO Platform Read/Write Syscall Checks
CVE-2025-21687
What is CVE-2025-21687?
A vulnerability exists in the Linux kernel's VFIO platform due to inadequate validation of parameters passed from user space through read/write syscalls. Specifically, while the offset is limited to 40 bits, the count parameter lacks proper bounds checking, enabling an attacker to read from or write to memory locations outside the intended device bounds. This oversight could lead to data corruption or unauthorized access to sensitive data, making it critical for system administrators to apply the necessary updates to safeguard their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Linux 6e3f264560099869f68830cb14b3b3e71e5ac76a
Linux 6e3f264560099869f68830cb14b3b3e71e5ac76a < 9377cdc118cf327248f1a9dde7b87de067681dc9
Linux 6e3f264560099869f68830cb14b3b3e71e5ac76a
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved