CVE-2025-21734

HIGH

Linux Kernel 5.2-6.1.128, 6.2-6.6.77, 6.7-6.12.13, 6.13-6.13.2 - Out-of-bounds Write in fastrpc Buffer Copy

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: Fix copy buffer page size For non-registered buffer, fastrpc driver copies the buffer and pass it to the remote subsystem. There is a problem with current implementation of page size calculation which is not considering the offset in the calculation. This might lead to passing of improper and out-of-bounds page size which could result in memory issue. Calculate page start and page end using the offset adjusted address instead of absolute address.

Scores

CVSS v3 7.8
EPSS 0.0019
EPSS Percentile 8.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (17)
linux/Kernel 5.2.0 - 6.1.129linux
linux/Kernel 6.13.0 - 6.13.3linux
linux/Kernel 6.2.0 - 6.6.78linux
linux/Kernel 6.7.0 - 6.12.14linux
Linux/Linux < 5.2
Linux/Linux 02b45b47fbe84e23699bb6bdc74d4c2780e282b4 - 24a79c6bc8de763f7c50f4f84f8b0c183bc25a51
Linux/Linux 02b45b47fbe84e23699bb6bdc74d4c2780e282b4 - c0464bad0e85fcd5d47e4297d1e410097c979e55
Linux/Linux 02b45b47fbe84e23699bb6bdc74d4c2780e282b4 - c3f7161123fcbdc64e90119ccce292d8b66281c4
Linux/Linux 02b45b47fbe84e23699bb6bdc74d4c2780e282b4 - c56ba3ea8e3c9a69a992aad18f7a65e43e51d623
Linux/Linux 02b45b47fbe84e23699bb6bdc74d4c2780e282b4 - e966eae72762ecfdbdb82627e2cda48845b9dd66
... and 7 more
Published Feb 27, 2025
Tracked Since Feb 18, 2026