CVE-2025-21800

HIGH

Linux Kernel 6.12-6.12.12, 6.13-6.13.1, 6.14 - Integer Overflow via Negative Bit Offset in HWS_SET32 Macro

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: net/mlx5: HWS, fix definer's HWS_SET32 macro for negative offset When bit offset for HWS_SET32 macro is negative, UBSAN complains about the shift-out-of-bounds: UBSAN: shift-out-of-bounds in drivers/net/ethernet/mellanox/mlx5/core/steering/hws/definer.c:177:2 shift exponent -8 is negative

Scores

CVSS v3 7.8
EPSS 0.0020
EPSS Percentile 10.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (11)
linux/Kernel 6.12.0 - 6.12.13linux
linux/Kernel 6.13.0 - 6.13.2linux
Linux/Linux < 6.12
Linux/Linux 6.12
Linux/Linux 6.12.13 - 6.12.*
Linux/Linux 6.13.2 - 6.13.*
Linux/Linux 6.14
Linux/Linux 74a778b4a63faef9ff02aad0d332b209835f93e1 - 69c676c0ded472713e6d1b3a456b3c4f52f66f0e
Linux/Linux 74a778b4a63faef9ff02aad0d332b209835f93e1 - 92cff996624c4757d5bbace3dfa3f1567ba94143
Linux/Linux 74a778b4a63faef9ff02aad0d332b209835f93e1 - be482f1d10da781db9445d2753c1e3f1fd82babf
... and 1 more
Published Feb 27, 2025
Tracked Since Feb 18, 2026