Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations
Name CVE-2025-21687 First vendor Publication 2025-02-10
Vendor Cve Last vendor Modification 2025-02-21

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Overall CVSS Score 7.8
Base Score 7.8 Environmental Score 7.8
impact SubScore 5.9 Temporal Score 7.8
Exploitabality Sub Score 1.8
 
Attack Vector Local Attack Complexity Low
Privileges Required Low User Interaction None
Scope Unchanged Confidentiality Impact High
Integrity Impact High Availability Impact High
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

In the Linux kernel, the following vulnerability has been resolved:

vfio/platform: check the bounds of read/write syscalls

count and offset are passed from user space and not checked, only offset is capped to 40 bits, which can be used to read/write out of bounds of the device.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-21687

CWE : Common Weakness Enumeration

% Id Name
50 % CWE-787 Out-of-bounds Write (CWE/SANS Top 25)
50 % CWE-125 Out-of-bounds Read

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 8
Os 3680

Sources (Detail)

https://git.kernel.org/stable/c/1485932496a1b025235af8aa1e21988d6b7ccd54
https://git.kernel.org/stable/c/665cfd1083866f87301bbd232cb8ba48dcf4acce
https://git.kernel.org/stable/c/6bcb8a5b70b80143db9bf12dfa7d53636f824d53
https://git.kernel.org/stable/c/92340e6c5122d823ad064984ef7513eba9204048
https://git.kernel.org/stable/c/a20fcaa230f7472456d12cf761ed13938e320ac3
https://git.kernel.org/stable/c/c981c32c38af80737a2fedc16e270546d139ccdd
https://git.kernel.org/stable/c/ce9ff21ea89d191e477a02ad7eabf4f996b80a69
https://git.kernel.org/stable/c/d19a8650fd3d7aed8d1af1d9a77f979a8430eba1
https://git.kernel.org/stable/c/f21636f24b6786c8b13f1af4319fa75ffcf17f38
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
Date Informations
2025-02-21 21:20:40
  • Multiple Updates
2025-02-21 17:20:33
  • Multiple Updates
2025-02-17 17:20:32
  • Multiple Updates
2025-02-10 21:20:29
  • First insertion