CVE-2025-22104
Vulnerability Summary
Timeline
Description
In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Use kernel helpers for hex dumps Previously, when the driver was printing hex dumps, the buffer was cast to an 8 byte long and printed using string formatters. If the buffer size was not a multiple of 8 then a read buffer overflow was possible. Therefore, create a new ibmvnic function that loops over a buffer and calls hex_dump_to_buffer instead. This patch address KASAN reports like the one below: ibmvnic 30000003 env3: Login Buffer: ibmvnic 30000003 env3: 01000000af000000 <...> ibmvnic 30000003 env3: 2e6d62692e736261 ibmvnic 30000003 env3: 65050003006d6f63 ================================================================== BUG: KASAN: slab-out-of-bounds in ibmvnic_login+0xacc/0xffc [ibmvnic] Read of size 8 at addr c0000001331a9aa8 by task ip/17681 <...> Allocated by task 17681: <...> ibmvnic_login+0x2f0/0xffc [ibmvnic] ibmvnic_open+0x148/0x308 [ibmvnic] __dev_open+0x1ac/0x304 <...> The buggy address is located 168 bytes inside of allocated 175-byte region [c0000001331a9a00, c0000001331a9aaf) <...> ================================================================= ibmvnic 30000003 env3: 000000000033766e
CVSS Metrics
- v3.1•HIGH•Score: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
EPSS Trends
Current EPSS score: 0.23%• Percentile: 14%
Techniques & Countermeasures
- CWE-125•Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
Affected Systems
- chainguard•linux-aws-6.12
< 6.12.67-r0 | < 6.12.60-r4 | < 6.12.77-r0 | < 6.12.65-r0 | < 6.12.72-r1 | < 6.12.74-r0 | < 6.12.68-r1 | < 6.12.65-r1 | < 6.12.74-r1 | < 6.12.62-r2 | < 6.12.80-r0 | < 6.12.68-r0 | < 6.12.77-r2 | < 6.12.71-r0 | < 6.12.72-r0 | < 6.12.76-r0 | < 6.12.66-r0 | < 6.12.77-r1 | < 6.12.57-r2 | < 6.12.78-r0 | < 6.12.65-r2 | < 6.12.63-r0 | < 6.12.62-r0 | < 6.12.62-r1 | < 6.12.70-r0 | < 6.12.69-r0
- chainguard•linux-azure-6.12
< 6.12.62-r0 | < 6.12.74-r0 | < 6.12.65-r1 | < 6.12.60-r3 | < 6.12.67-r0 | < 6.12.65-r4 | < 6.12.77-r0 | < 6.12.71-r0 | < 6.12.77-r1 | < 6.12.62-r1 | < 6.12.74-r1 | < 6.12.66-r0 | < 6.12.65-r2 | < 6.12.60-r4 | < 6.12.78-r0 | < 6.12.69-r0 | < 6.12.68-r0 | < 6.12.76-r0 | < 6.12.65-r3 | < 6.12.80-r0 | < 6.12.62-r2 | < 6.12.70-r0 | < 6.12.72-r0 | < 6.12.63-r0 | < 6.12.57-r2 | < 6.12.77-r2
- chainguard•linux-gcp-6.12
< 6.12.68-r0 | < 6.12.77-r0 | < 6.12.77-r2 | < 6.12.65-r0 | < 6.12.71-r0 | < 6.12.63-r0 | < 6.12.69-r0 | < 6.12.65-r2 | < 6.12.70-r0 | < 6.12.76-r0 | < 6.12.60-r4 | < 6.12.74-r0 | < 6.12.72-r0 | < 6.12.57-r2 | < 6.12.60-r3 | < 6.12.65-r1 | < 6.12.66-r0 | < 6.12.62-r2 | < 6.12.77-r1 | < 6.12.78-r0 | < 6.12.67-r0 | < 6.12.68-r1 | < 6.12.80-r0 | < 6.12.74-r1 | < 6.12.62-r0 | < 6.12.62-r1
- chainguard•linux-qemu-6.12
< 6.12.72-r0 | < 6.12.67-r0 | < 6.12.77-r1 | < 6.12.78-r0 | < 6.12.66-r0 | < 6.12.65-r1 | < 6.12.76-r0 | < 6.12.74-r1 | < 6.12.77-r2 | < 6.12.65-r2 | < 6.12.71-r0 | < 6.12.77-r0 | < 6.12.70-r0 | < 6.12.80-r0 | < 6.12.68-r0 | < 6.12.74-r0 | < 6.12.69-r0
- chainguard•linux-vmware-6.12
< 6.12.77-r1 | < 6.12.76-r0 | < 6.12.71-r0 | < 6.12.74-r0 | < 6.12.66-r0 | < 6.12.68-r0 | < 6.12.78-r0 | < 6.12.69-r0 | < 6.12.72-r0 | < 6.12.67-r0 | < 6.12.68-r1 | < 6.12.77-r0 | < 6.12.65-r2 | < 6.12.80-r0 | < 6.12.77-r2 | < 6.12.74-r1 | < 6.12.65-r1 | < 6.12.70-r0
- debian•linux
all | all | < 6.1.187-1 | all | < 6.16.3-1
- ubuntu•linux
all | all | all
- ubuntu•linux-allwinner-5.19
all
- ubuntu•linux-aws
all | all | all
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.11
all
- ubuntu•linux-aws-5.13
all
- ubuntu•linux-aws-5.15
all
- ubuntu•linux-aws-5.19
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-5.4
all
- ubuntu•linux-aws-5.8
all
- ubuntu•linux-aws-6.2
all
- ubuntu•linux-aws-6.5
all
- ubuntu•linux-aws-6.8
all
- ubuntu•linux-aws-fips
all
- ubuntu•linux-aws-hwe
all
- ubuntu•linux-azure
all | all | all | all
- ubuntu•linux-azure-4.15
all
- ubuntu•linux-azure-5.11
all
- ubuntu•linux-azure-5.13
all
- ubuntu•linux-azure-5.15
all
- ubuntu•linux-azure-5.19
all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-5.4
all
- ubuntu•linux-azure-5.8
all
- ubuntu•linux-azure-6.11
all
- ubuntu•linux-azure-6.2
all
- ubuntu•linux-azure-6.5
all
- ubuntu•linux-azure-6.8
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all | all | all | all
- ubuntu•linux-azure-fde-5.19
all
- ubuntu•linux-azure-fde-6.17
all
- ubuntu•linux-azure-fde-6.2
all
- ubuntu•linux-azure-fde-6.8
all
- ubuntu•linux-azure-fips
all
- ubuntu•linux-azure-nvidia
all
- ubuntu•linux-bluefield
all | all
- ubuntu•linux-fips
all
- ubuntu•linux-gcp
all | all | all | all
- ubuntu•linux-gcp-4.15
all
- ubuntu•linux-gcp-5.11
all
- ubuntu•linux-gcp-5.13
all
- ubuntu•linux-gcp-5.15
all
Showing first 50 affected entries in server-rendered view.
References (13)
- https://git.kernel.org/stable/c/ae6b1d6c1acee3a2000394d83ec9f1028321e207
- https://git.kernel.org/stable/c/d93a6caab5d7d9b5ce034d75b1e1e993338e3852
- https://ubuntu.com/security/CVE-2025-22104
- https://www.cve.org/CVERecord?id=CVE-2025-22104
- https://git.kernel.org/linus/d93a6caab5d7d9b5ce034d75b1e1e993338e3852
- https://ubuntu.com/security/notices/USN-7594-1
- https://ubuntu.com/security/notices/USN-7594-2
- https://ubuntu.com/security/notices/USN-7594-3
- https://security-tracker.debian.org/tracker/CVE-2025-22104
- https://git.kernel.org/stable/c/19efa170e01207c8ada726f3f6c65b31fcba2a73
- https://git.kernel.org/stable/c/9bc078818ec76344c2e06b81d7aee2df3adecfbf
- https://git.kernel.org/stable/c/005fee039dd845122d313ac8f2122b0d09dc5d7b
- https://ubuntu.com/security/notices/USN-8781-1