xsk: fix an integer overflow in xp_create_and_assign_umem()
Published Apr 3, 2025
7.1
HIGHCVSS 3.1
EPSS 0.20%
Description
Since the i and pool->chunk_size variables are of type 'u32', their product can wrap around and then be cast to 'u64'. This can lead to two different XDP buffers pointing to the same memory area.
Found by InfoTeCS on behalf of Linux Verification Center (linuxtesting.org) with SVACE.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 5.16StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<5.16
- Version 6.1.132StatusunaffectedConstraints<=6.1.*
- Version 6.12.21StatusunaffectedConstraints<=6.12.*
- Version 6.13.9StatusunaffectedConstraints<=6.13.*
- Version 6.14StatusunaffectedConstraints<=*
- Version 6.6.85StatusunaffectedConstraints<=6.6.*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Linux | Linux | unaffected |
| ||||||||||||||||||||||||
| Linux | Linux | affected |
|
- ≥ 5.16 · < 6.1.132
- ≥ 6.2 · < 6.6.85
- ≥ 6.7 · < 6.12.21
- ≥ 6.13 · < 6.13.9
- 6.14
- 6.14
- 6.14
- 6.14
- 6.14
- 6.14
- 6.14
No data.
Red Hat Enterprise Linux 10
kernel-0:6.12.0-55.16.1.el10_0
Fixed · RHSA-2025:8669
Red Hat Enterprise Linux 9
kernel-0:5.14.0-570.21.1.el9_6
Fixed · RHSA-2025:8643
Red Hat Enterprise Linux 9
kernel-0:5.14.0-570.21.1.el9_6
Fixed · RHSA-2025:8643
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Out of support scope
Red Hat Enterprise Linux 8
kernel-rt
Out of support scope
Red Hat Enterprise Linux 9
kernel-rt
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel-0:6.12.0-55.16.1.el10_0 | Fixed | RHSA-2025:8669 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-570.21.1.el9_6 | Fixed | RHSA-2025:8643 |
| Red Hat Enterprise Linux 9 | kernel-0:5.14.0-570.21.1.el9_6 | Fixed | RHSA-2025:8643 |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Oct 1, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2025-2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.20% (0.00204) | 9.41th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.16% (0.00156) | 5.05th | v5 (v2026.06.15) |
| Apr 3, 2025 | 0.02% (0.00018) | 2.48th | v4 (v2025.03.14) |
References (11)
- https://access.redhat.com/security/cve/CVE-2025-21997 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2357143 Issue Tracking
- https://git.kernel.org/stable/c/130290f44bce0eead2b827302109afc3fe189ddd Patch
- https://git.kernel.org/stable/c/205649d642a5b376724f04f3a5b3586815e43d3b Patch
- https://git.kernel.org/stable/c/559847f56769037e5b2e0474d3dbff985b98083d Patch
- https://git.kernel.org/stable/c/b7b4be1fa43294b50b22e812715198629806678a Patch
- https://git.kernel.org/stable/c/c7670c197b0f1a8726ad5c87bc2bf001a1fc1bbd Patch
- https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
- https://lore.kernel.org/linux-cve-announce/2025040348-CVE-2025-21997-492c@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-21997
- https://www.cve.org/CVERecord?id=CVE-2025-21997
Change history (0)
No recorded changes yet.