SB2025022781 - Out-of-bounds read in Linux kernel loongarch lib
Published: February 27, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2025-21789)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to an out-of-bounds read error within the do_csum() function in arch/loongarch/lib/csum.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/6287f1a8c16138c2ec750953e35039634018c84a
- https://git.kernel.org/stable/c/964a8895704a22efc06a2a3276b624a5ae985a06
- https://git.kernel.org/stable/c/9f15a8df542c0f08732a67d1a14ee7c22948fb97
- https://git.kernel.org/stable/c/d6508ffff32b44b6d0de06704034e4eef1c307a7
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.4