CVE-2025-21724

HIGH

Linux Kernel - Out-of-bounds Write in iova_bitmap_offset_to_index

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: iommufd/iova_bitmap: Fix shift-out-of-bounds in iova_bitmap_offset_to_index() Resolve a UBSAN shift-out-of-bounds issue in iova_bitmap_offset_to_index() where shifting the constant "1" (of type int) by bitmap->mapped.pgshift (an unsigned long value) could result in undefined behavior. The constant "1" defaults to a 32-bit "int", and when "pgshift" exceeds 31 (e.g., pgshift = 63) the shift operation overflows, as the result cannot be represented in a 32-bit type. To resolve this, the constant is updated to "1UL", promoting it to an unsigned long type to match the operand's type.

Scores

CVSS v3 7.8
EPSS 0.0018
EPSS Percentile 7.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (17)
linux/Kernel 6.1.0 - 6.1.129linux
linux/Kernel 6.13.0 - 6.13.2linux
linux/Kernel 6.2.0 - 6.6.76linux
linux/Kernel 6.7.0 - 6.12.13linux
Linux/Linux < 6.1
Linux/Linux 58ccf0190d19d9a8a41f8a02b9e06742b58df4a1 - 38ac76fc06bc6826a3e4b12a98efbe98432380a9
Linux/Linux 58ccf0190d19d9a8a41f8a02b9e06742b58df4a1 - 44d9c94b7a3f29a3e07c4753603a35e9b28842a3
Linux/Linux 58ccf0190d19d9a8a41f8a02b9e06742b58df4a1 - b1f8453b8ff1ab79a03820ef608256c499769cb6
Linux/Linux 58ccf0190d19d9a8a41f8a02b9e06742b58df4a1 - d5d33f01b86af44b23eea61ee309e4ef22c0cdfe
Linux/Linux 58ccf0190d19d9a8a41f8a02b9e06742b58df4a1 - e24c1551059268b37f6f40639883eafb281b8b9c
... and 7 more
Published Feb 27, 2025
Tracked Since Feb 18, 2026