Linux Kernel Vulnerability with VFIO Platform Read/Write Syscall Checks
CVE-2025-21687
Summary
A vulnerability exists in the Linux kernel's VFIO platform due to inadequate validation of parameters passed from user space through read/write syscalls. Specifically, while the offset is limited to 40 bits, the count parameter lacks proper bounds checking, enabling an attacker to read from or write to memory locations outside the intended device bounds. This oversight could lead to data corruption or unauthorized access to sensitive data, making it critical for system administrators to apply the necessary updates to safeguard their systems.
Affected Version(s)
Linux 6e3f264560099869f68830cb14b3b3e71e5ac76a
Linux 6e3f264560099869f68830cb14b3b3e71e5ac76a
Linux 6e3f264560099869f68830cb14b3b3e71e5ac76a < 92340e6c5122d823ad064984ef7513eba9204048
References
Timeline
Vulnerability published
Vulnerability Reserved