CVE-2025-22104

Aliases:UBUNTU-CVE-2025-22104DEBIAN-CVE-2025-22104CGA-22q6-4836-ffxwCGA-23j3-qqf9-7577CGA-27pj-68mw-p3mwCGA-2mqv-6x7p-xcmgCGA-2ppw-4rm7-787fCGA-2q82-pwrh-3hpwCGA-2r33-57j7-2pgvCGA-2vr8-76gm-qhhxCGA-2xx3-9g9j-2xf5CGA-32cm-qcff-q8rqCGA-3c42-gw6f-9q6rCGA-3mqg-78f7-grj8CGA-3vxm-6pw8-rj4mCGA-424f-rwff-4pv4CGA-43qj-gxwx-hm85CGA-45xp-2h23-cp5fCGA-49j7-5g4r-9x86CGA-49p7-48qv-jh2wCGA-4p8p-m9fh-qc85CGA-4vhj-xmmq-wrv6CGA-57mc-82p7-3p96CGA-5c25-27vw-fjphCGA-5chm-733g-9234CGA-5g6x-42gg-64rcCGA-5h6v-g3wg-qgpfCGA-5qh3-cjwm-pmp4CGA-67r9-gf39-4h2cCGA-6fhx-h8qh-rvc2CGA-6gff-mvjv-9vr7CGA-6rqx-fxv9-cq45CGA-6rvf-jg2h-qh4cCGA-74fg-2hr2-c7g8CGA-75p3-xgrp-2w54CGA-7cfv-vmfq-w336CGA-7cx3-vm59-f3jpCGA-7m8c-55gh-3mjmCGA-7mv4-q59h-3mp5CGA-85hx-f448-h33fCGA-85xf-cww6-3p3vCGA-87wg-hm5g-97p3CGA-8g5f-6qx2-f3wvCGA-8gh2-v3qq-5q64CGA-8hpp-963v-rg5jCGA-8v4q-7wm8-qv54CGA-94gf-jchg-g4xjCGA-96cf-rc79-f8gxCGA-9jm7-vqm3-fv9jCGA-9rqr-mwq4-2pw6CGA-cq44-4v78-q3x2CGA-cq9c-273w-j357CGA-cqc4-pgm3-h7qcCGA-crqc-v55c-c2hjCGA-cv47-q25f-fpr9CGA-cvmg-h7w6-q36fCGA-cwvm-553j-rhr8CGA-cx4g-8754-r62vCGA-cxx7-qmfw-p66pCGA-f3vw-2q66-2ggvCGA-ff54-94g8-g5j2CGA-ffmq-59fq-j2f3CGA-fhp6-j5xg-gwfxCGA-g26g-jgmm-8v7rCGA-g72x-4hq4-5g4gCGA-gfgm-w5qj-wg2qCGA-gp5w-v6mg-xv8vCGA-gx9m-3gjw-v98qCGA-h2h9-85jj-xp62CGA-hhqh-m5rj-2w6xCGA-hhvq-3x23-5w7rCGA-jh8j-3cfq-2gwwCGA-jhvx-gg5v-q93cCGA-jxq7-fr7w-qh4cCGA-m4c3-7rvr-p49qCGA-mc6w-86j9-r5j9CGA-mg3g-3wp3-7hchCGA-mh2g-xj86-q4f7CGA-mj7g-24wx-56rwCGA-mqwr-65rj-8x58CGA-p2px-fwvg-vgmvCGA-p577-rr4g-q54fCGA-pfgr-w63c-w9w2CGA-pfp9-9p76-g52rCGA-phjv-x8vq-3c8jCGA-pm3h-8hp8-7qxjCGA-pq7q-mxfh-9mphCGA-pqpf-w4xq-6486CGA-pwpf-fph6-fw7qCGA-q27g-8h9c-q7jhCGA-q4rv-qjv6-324hCGA-qffm-hxfc-6787CGA-qpmq-44ph-w4xgCGA-qr2g-2x3j-pv6rCGA-qx4f-6f9p-wr9cCGA-qx8w-j323-4cx9CGA-r529-rmg9-4228CGA-r7qf-f3f9-j5f6CGA-rc85-3wgw-prmgCGA-rhx8-x794-q2jqCGA-rpxq-rc5r-m8crCGA-v6wq-6h79-85pxCGA-v79x-8xgv-jj97CGA-v822-9vqw-839gCGA-vcp7-6wfm-mrxvCGA-vjrw-94fj-82c6CGA-vm2r-q2g3-g4cvCGA-vqgw-43jx-4r82CGA-vx6f-hp88-cc84CGA-w483-5g4x-9jxwCGA-wf85-v57m-89m3CGA-wjfm-98x5-xj9mCGA-wpph-7xm4-w3w8CGA-wq6f-p2p5-63f4CGA-wr56-x2p3-w4qxCGA-ww6f-c2pw-8j2hCGA-xgph-v5jr-4h5mCGA-xmpv-r6f6-9q87CGA-xpvf-c54c-vrwmCGA-xvxh-j399-h454
Advisory lineage Upstream: 0 Downstream: 25
Modified
Published: 16 Apr 2025, 14:12
Last modified:02 Sept 2026, 12:49

Vulnerability Summary

Overall Risk (default)
medium
28/100
CVSS Score
7.1 HIGH
v3.1 (nvd)
EPSS Score
0.23% LOW
0% probability +0.20%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Apr 2025, 14:12
Published
Vulnerability first disclosed
02 Sept 2026, 12:49
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: ibmvnic: Use kernel helpers for hex dumps Previously, when the driver was printing hex dumps, the buffer was cast to an 8 byte long and printed using string formatters. If the buffer size was not a multiple of 8 then a read buffer overflow was possible. Therefore, create a new ibmvnic function that loops over a buffer and calls hex_dump_to_buffer instead. This patch address KASAN reports like the one below: ibmvnic 30000003 env3: Login Buffer: ibmvnic 30000003 env3: 01000000af000000 <...> ibmvnic 30000003 env3: 2e6d62692e736261 ibmvnic 30000003 env3: 65050003006d6f63 ================================================================== BUG: KASAN: slab-out-of-bounds in ibmvnic_login+0xacc/0xffc [ibmvnic] Read of size 8 at addr c0000001331a9aa8 by task ip/17681 <...> Allocated by task 17681: <...> ibmvnic_login+0x2f0/0xffc [ibmvnic] ibmvnic_open+0x148/0x308 [ibmvnic] __dev_open+0x1ac/0x304 <...> The buggy address is located 168 bytes inside of allocated 175-byte region [c0000001331a9a00, c0000001331a9aaf) <...> ================================================================= ibmvnic 30000003 env3: 000000000033766e

CVSS Metrics

  • v3.1HIGHScore: 7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

EPSS Trends

Current EPSS score: 0.23% Percentile: 14%

Techniques & Countermeasures

  • CWE-125Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • chainguardlinux-aws-6.12

    < 6.12.67-r0 | < 6.12.60-r4 | < 6.12.77-r0 | < 6.12.65-r0 | < 6.12.72-r1 | < 6.12.74-r0 | < 6.12.68-r1 | < 6.12.65-r1 | < 6.12.74-r1 | < 6.12.62-r2 | < 6.12.80-r0 | < 6.12.68-r0 | < 6.12.77-r2 | < 6.12.71-r0 | < 6.12.72-r0 | < 6.12.76-r0 | < 6.12.66-r0 | < 6.12.77-r1 | < 6.12.57-r2 | < 6.12.78-r0 | < 6.12.65-r2 | < 6.12.63-r0 | < 6.12.62-r0 | < 6.12.62-r1 | < 6.12.70-r0 | < 6.12.69-r0

  • chainguardlinux-azure-6.12

    < 6.12.62-r0 | < 6.12.74-r0 | < 6.12.65-r1 | < 6.12.60-r3 | < 6.12.67-r0 | < 6.12.65-r4 | < 6.12.77-r0 | < 6.12.71-r0 | < 6.12.77-r1 | < 6.12.62-r1 | < 6.12.74-r1 | < 6.12.66-r0 | < 6.12.65-r2 | < 6.12.60-r4 | < 6.12.78-r0 | < 6.12.69-r0 | < 6.12.68-r0 | < 6.12.76-r0 | < 6.12.65-r3 | < 6.12.80-r0 | < 6.12.62-r2 | < 6.12.70-r0 | < 6.12.72-r0 | < 6.12.63-r0 | < 6.12.57-r2 | < 6.12.77-r2

  • chainguardlinux-gcp-6.12

    < 6.12.68-r0 | < 6.12.77-r0 | < 6.12.77-r2 | < 6.12.65-r0 | < 6.12.71-r0 | < 6.12.63-r0 | < 6.12.69-r0 | < 6.12.65-r2 | < 6.12.70-r0 | < 6.12.76-r0 | < 6.12.60-r4 | < 6.12.74-r0 | < 6.12.72-r0 | < 6.12.57-r2 | < 6.12.60-r3 | < 6.12.65-r1 | < 6.12.66-r0 | < 6.12.62-r2 | < 6.12.77-r1 | < 6.12.78-r0 | < 6.12.67-r0 | < 6.12.68-r1 | < 6.12.80-r0 | < 6.12.74-r1 | < 6.12.62-r0 | < 6.12.62-r1

  • chainguardlinux-qemu-6.12

    < 6.12.72-r0 | < 6.12.67-r0 | < 6.12.77-r1 | < 6.12.78-r0 | < 6.12.66-r0 | < 6.12.65-r1 | < 6.12.76-r0 | < 6.12.74-r1 | < 6.12.77-r2 | < 6.12.65-r2 | < 6.12.71-r0 | < 6.12.77-r0 | < 6.12.70-r0 | < 6.12.80-r0 | < 6.12.68-r0 | < 6.12.74-r0 | < 6.12.69-r0

  • chainguardlinux-vmware-6.12

    < 6.12.77-r1 | < 6.12.76-r0 | < 6.12.71-r0 | < 6.12.74-r0 | < 6.12.66-r0 | < 6.12.68-r0 | < 6.12.78-r0 | < 6.12.69-r0 | < 6.12.72-r0 | < 6.12.67-r0 | < 6.12.68-r1 | < 6.12.77-r0 | < 6.12.65-r2 | < 6.12.80-r0 | < 6.12.77-r2 | < 6.12.74-r1 | < 6.12.65-r1 | < 6.12.70-r0

  • debianlinux

    all | all | < 6.1.187-1 | all | < 6.16.3-1

  • ubuntulinux

    all | all | all

  • ubuntulinux-allwinner-5.19

    all

  • ubuntulinux-aws

    all | all | all

  • ubuntulinux-aws-5.0

    all

  • ubuntulinux-aws-5.11

    all

  • ubuntulinux-aws-5.13

    all

  • ubuntulinux-aws-5.15

    all

  • ubuntulinux-aws-5.19

    all

  • ubuntulinux-aws-5.3

    all

  • ubuntulinux-aws-5.4

    all

  • ubuntulinux-aws-5.8

    all

  • ubuntulinux-aws-6.2

    all

  • ubuntulinux-aws-6.5

    all

  • ubuntulinux-aws-6.8

    all

  • ubuntulinux-aws-fips

    all

  • ubuntulinux-aws-hwe

    all

  • ubuntulinux-azure

    all | all | all | all

  • ubuntulinux-azure-4.15

    all

  • ubuntulinux-azure-5.11

    all

  • ubuntulinux-azure-5.13

    all

  • ubuntulinux-azure-5.15

    all

  • ubuntulinux-azure-5.19

    all

  • ubuntulinux-azure-5.3

    all

  • ubuntulinux-azure-5.4

    all

  • ubuntulinux-azure-5.8

    all

  • ubuntulinux-azure-6.11

    all

  • ubuntulinux-azure-6.2

    all

  • ubuntulinux-azure-6.5

    all

  • ubuntulinux-azure-6.8

    all

  • ubuntulinux-azure-edge

    all

  • ubuntulinux-azure-fde

    all | all | all | all

  • ubuntulinux-azure-fde-5.19

    all

  • ubuntulinux-azure-fde-6.17

    all

  • ubuntulinux-azure-fde-6.2

    all

  • ubuntulinux-azure-fde-6.8

    all

  • ubuntulinux-azure-fips

    all

  • ubuntulinux-azure-nvidia

    all

  • ubuntulinux-bluefield

    all | all

  • ubuntulinux-fips

    all

  • ubuntulinux-gcp

    all | all | all | all

  • ubuntulinux-gcp-4.15

    all

  • ubuntulinux-gcp-5.11

    all

  • ubuntulinux-gcp-5.13

    all

  • ubuntulinux-gcp-5.15

    all

Showing first 50 affected entries in server-rendered view.

References (13)