CVE-2025-21785
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Feb 27, 2025
Updated: Mar 13, 2025
CWE ID 787
Summary
CVE-2025-21785 is a vulnerability affecting the Linux kernel's cacheinfo subsystem on arm64 architecture. The issue stems from a failure to account for cache levels with separate data/instruction caches when detecting and populating cache information. Consequently, there is a risk of an out-of-bounds write to the cacheinfo array. This flaw has been resolved by adjusting the index incrementation for any populated leaf, rather than level, to prevent unintended array access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.