SB2025031033 - Buffer overflow in Linux kernel io_uring
Published: March 10, 2025 Updated: May 11, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2025-21836)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory corruption within the io_destroy_buffers() and io_register_pbuf_ring() functions in io_uring/kbuf.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/146a185f6c05ee263db715f860620606303c4633
- https://git.kernel.org/stable/c/2a5febbef40ce968e295a7aeaa5d5cbd9e3e5ad4
- https://git.kernel.org/stable/c/7d0dc28dae836caf7645fef62a10befc624dd17b
- https://git.kernel.org/stable/c/8802766324e1f5d414a81ac43365c20142e85603
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.16
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.6.79