CVE-2025-21785

Advisory lineage Upstream: 0 Downstream: 71
Modified
Published: 27 Feb 2025, 02:18
Last modified:11 May 2026, 21:06

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.8 HIGH
v3.1 (nvd)
EPSS Score
0.01% LOW
0% probability -0.03%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

27 Feb 2025, 02:18
Published
Vulnerability first disclosed
11 May 2026, 21:06
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array The loop that detects/populates cache information already has a bounds check on the array size but does not account for cache levels with separate data/instructions cache. Fix this by incrementing the index for any populated leaf (instead of any populated level).

CVSS Metrics

  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.01% Percentile: 4%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • linuxlinux

    ≥ 5d425c18653731af62831d30a4fa023d532657a9, < 4371ac7b494e933fffee2bd6265d18d73c4f05aa | ≥ 5d425c18653731af62831d30a4fa023d532657a9, < e4fde33107351ec33f1a64188612fbc6ca659284 | ≥ 5d425c18653731af62831d30a4fa023d532657a9, < 88a3e6afaf002250220793df99404977d343db14 | ≥ 5d425c18653731af62831d30a4fa023d532657a9, < 4ff25f0b18d1d0174c105e4620428bcdc1213860 | ≥ 5d425c18653731af62831d30a4fa023d532657a9, < ab90894f33c15b14c1cee6959ab6c8dcb09127f8 | ≥ 5d425c18653731af62831d30a4fa023d532657a9, < 715eb1af64779e1b1aa0a7b2ffb81414d9f708e5 | ≥ 5d425c18653731af62831d30a4fa023d532657a9, < 67b99a2b5811df4294c2ad50f9bff3b6a08bd618 | ≥ 5d425c18653731af62831d30a4fa023d532657a9, < 875d742cf5327c93cba1f11e12b08d3cce7a88d2 | 4.0

  • linuxlinux_kernel

    ≥ 4.0, < 6.1.129 | ≥ 6.2, < 6.6.79 | ≥ 6.7, < 6.12.16 | ≥ 6.13, < 6.13.4 | 6.14:rc1 | 6.14:rc2

References (10)