CVE-2025-21704
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: usb: cdc-acm: Check control transfer buffer size before access If the first fragment is shorter than struct usb_cdc_notification, we can't calculate an expected_size. Log an error and discard the notification instead of reading lengths from memory outside the received data, which can lead to memory corruption when the expected_size decreases between fragments, causing `expected_size - acm->nb_index` to wrap. This issue has been present since the beginning of git history; however, it only leads to memory corruption since commit ea2583529cd1 ("cdc-acm: reassemble fragmented notifications"). A mitigating factor is that acm_ctrl_irq() can only execute after userspace has opened /dev/ttyACM*; but if ModemManager is running, ModemManager will do that automatically depending on the USB device's vendor/product IDs and its other interfaces.
CVSS Metrics
- v3.1•HIGH•Score: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 0.36%• Percentile: 29%
Techniques & Countermeasures
- CWE-787•Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
Affected Systems
- debian•linux
< 5.10.237-1 | < 6.1.129-1 | < 6.12.16-1 | < 6.12.16-1
- debian•linux-6.1
< 6.1.129-1~deb11u1
- ubuntu•linux
all | < 4.4.0-278.312 | < 4.15.0-247.259 | < 5.4.0-216.236 | < 5.15.0-140.150 | < 6.8.0-78.78
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
< 4.4.0-1152.158 | < 4.4.0-1190.205 | < 4.15.0-1189.202 | < 5.4.0-1146.156 | < 5.15.0-1084.91 | < 6.8.0-1035.37
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
< 5.15.0-1084.91~20.04.1
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
< 5.4.0-1146.156~18.04.1
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.2
all
- ubuntu•linux-aws-6.5
all
- ubuntu•linux-aws-6.8
< 6.8.0-1035.37~22.04.1
- ubuntu•linux-aws-fips
< 4.15.0-2127.133 | all | < 5.4.0-1146.156+fips1 | < 5.15.0-1084.91+fips1
- ubuntu•linux-aws-hwe
< 4.15.0-1189.202~16.04.1
- ubuntu•linux-azure
< 4.15.0-1197.212~14.04.1 | < 4.15.0-1197.212~16.04.1 | all | < 5.4.0-1151.158 | < 5.15.0-1089.98 | < 6.8.0-1034.39
- ubuntu•linux-azure-4.15
< 4.15.0-1197.212
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
< 5.15.0-1089.98~20.04.1
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
< 5.4.0-1151.158~18.04.1
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.11
< 6.11.0-1015.15~24.04.1
- ubuntu•linux-azure-6.2
all
- ubuntu•linux-azure-6.5
all
- ubuntu•linux-azure-6.8
< 6.8.0-1034.39~22.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | all
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.2
all
- ubuntu•linux-azure-fips
< 4.15.0-2106.112 | all | < 5.4.0-1151.158+fips1 | < 5.15.0-1089.98+fips1
- ubuntu•linux-azure-nvidia
< 6.8.0-1022.23
- ubuntu•linux-bluefield
all | < 5.4.0-1105.112 | < 5.15.0-1066.68
- ubuntu•linux-fips
< 4.4.0-1122.129 | all | < 4.15.0-1144.156 | < 5.4.0-1120.130 | < 5.15.0-140.150+fips1 | < 6.8.0-78.78+fips1
- ubuntu•linux-gcp
< 4.15.0-1182.199~16.04.1 | all | < 5.4.0-1149.158 | < 5.15.0-1083.92 | < 6.8.0-1036.38
- ubuntu•linux-gcp-4.15
< 4.15.0-1182.199
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
- ubuntu•linux-gcp-5.15
< 5.15.0-1083.92~20.04.1
- ubuntu•linux-gcp-5.19
all
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1149.158~18.04.1
- ubuntu•linux-gcp-5.8
all
- ubuntu•linux-gcp-6.11
< 6.11.0-1015.15~24.04.1
- ubuntu•linux-gcp-6.2
all
Showing first 50 affected entries in server-rendered view.
References (63)
- https://git.kernel.org/stable/c/a4e1ae5c0533964170197e4fb4f33bc8c1db5cd2
- https://git.kernel.org/stable/c/90dd2f1b7342b9a671a5ea4160f408037b92b118
- https://git.kernel.org/stable/c/871619c2b78fdfe05afb4e8ba548678687beb812
- https://git.kernel.org/stable/c/7828e9363ac4d23b02419bf2a45b9f1d9fb35646
- https://git.kernel.org/stable/c/6abb510251e75f875797d8983a830e6731fa281c
- https://git.kernel.org/stable/c/f64079bef6a8a7823358c3f352ea29a617844636
- https://git.kernel.org/stable/c/383d516a0ebc8641372b521c8cb717f0f1834831
- https://git.kernel.org/stable/c/e563b01208f4d1f609bcab13333b6c0e24ce6a01
- https://project-zero.issues.chromium.org/issues/395107243
- https://lists.debian.org/debian-lts-announce/2025/05/msg00030.html
- https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html
- https://cert-portal.siemens.com/productcert/html/ssa-265688.html
- https://ubuntu.com/security/CVE-2025-21704
- https://www.cve.org/CVERecord?id=CVE-2025-21704
- https://git.kernel.org/linus/e563b01208f4d1f609bcab13333b6c0e24ce6a01
- https://ubuntu.com/security/notices/USN-7510-1
- https://ubuntu.com/security/notices/USN-7510-2
- https://ubuntu.com/security/notices/USN-7511-1
- https://ubuntu.com/security/notices/USN-7511-2
- https://ubuntu.com/security/notices/USN-7512-1
- https://ubuntu.com/security/notices/USN-7516-1
- https://ubuntu.com/security/notices/USN-7516-2
- https://ubuntu.com/security/notices/USN-7517-1
- https://ubuntu.com/security/notices/USN-7518-1
- https://ubuntu.com/security/notices/USN-7521-1
- https://ubuntu.com/security/notices/USN-7510-3
- https://ubuntu.com/security/notices/USN-7510-4
- https://ubuntu.com/security/notices/USN-7510-5
- https://ubuntu.com/security/notices/USN-7511-3
- https://ubuntu.com/security/notices/USN-7516-3
- https://ubuntu.com/security/notices/USN-7516-4
- https://ubuntu.com/security/notices/USN-7517-2
- https://ubuntu.com/security/notices/USN-7521-2
- https://ubuntu.com/security/notices/USN-7516-5
- https://ubuntu.com/security/notices/USN-7516-6
- https://ubuntu.com/security/notices/USN-7517-3
- https://ubuntu.com/security/notices/USN-7510-6
- https://ubuntu.com/security/notices/USN-7521-3
- https://ubuntu.com/security/notices/USN-7510-7
- https://ubuntu.com/security/notices/USN-7539-1
- https://ubuntu.com/security/notices/USN-7540-1
- https://ubuntu.com/security/notices/USN-7516-7
- https://ubuntu.com/security/notices/USN-7516-8
- https://ubuntu.com/security/notices/USN-7510-8
- https://ubuntu.com/security/notices/USN-7516-9
- https://ubuntu.com/security/notices/USN-7593-1
- https://ubuntu.com/security/notices/USN-7602-1
- https://ubuntu.com/security/notices/USN-7640-1
- https://ubuntu.com/security/notices/USN-7703-1
- https://ubuntu.com/security/notices/USN-7703-2
- https://ubuntu.com/security/notices/USN-7703-3
- https://ubuntu.com/security/notices/USN-7719-1
- https://ubuntu.com/security/notices/USN-7703-4
- https://ubuntu.com/security/notices/USN-7737-1
- https://ubuntu.com/security/notices/USN-8070-1
- https://ubuntu.com/security/notices/USN-8070-2
- https://ubuntu.com/security/notices/USN-8070-3
- https://ubuntu.com/security/notices/USN-8112-1
- https://ubuntu.com/security/notices/USN-8112-2
- https://ubuntu.com/security/notices/USN-8112-3
- https://ubuntu.com/security/notices/USN-8112-4
- https://ubuntu.com/security/notices/USN-8112-5
- https://security-tracker.debian.org/tracker/CVE-2025-21704