CVE-2025-21680
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2025-21680 is a Linux kernel vulnerability affecting the pktgen module. This issue is caused by an out-of-bounds access in the function get_imix_entries, leading to an invalid access to pkt_dev->imix_entries array. The UBSAN (User Space Bound Checker) detected an array-index-out-of-bounds error at net/core/pktgen.c:874. The vulnerability was discovered on a QEMU Standard PC system with Linux kernel version 6.10.0-rc1 and PID 1210 running bash. The call trace shows the error occurring during pde_write, vfs_write, and do_syscall_64 system calls. The Linux Verification Center identified the flaw using SVACE and suggested allowing the array to be filled completely as a potential fix.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.