Linux Kernel Vulnerability with VFIO Platform Read/Write Syscall Checks
CVE-2025-21687

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
10 February 2025

What is CVE-2025-21687?

A vulnerability exists in the Linux kernel's VFIO platform due to inadequate validation of parameters passed from user space through read/write syscalls. Specifically, while the offset is limited to 40 bits, the count parameter lacks proper bounds checking, enabling an attacker to read from or write to memory locations outside the intended device bounds. This oversight could lead to data corruption or unauthorized access to sensitive data, making it critical for system administrators to apply the necessary updates to safeguard their systems.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Linux 6e3f264560099869f68830cb14b3b3e71e5ac76a

Linux 6e3f264560099869f68830cb14b3b3e71e5ac76a < 9377cdc118cf327248f1a9dde7b87de067681dc9

Linux 6e3f264560099869f68830cb14b3b3e71e5ac76a

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.