Wind River Support Network

HomeDefectsLIN1024-8405
Fixed

LIN1024-8405 : Security Advisory - linux - CVE-2025-21997

Created: Apr 6, 2025    Updated: Apr 11, 2025
Resolved Date: Apr 11, 2025
Found In Version: 10.24.33.1
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

xsk: fix an integer overflow in xp_create_and_assign_umem()

Since the i and pool->chunk_size variables are of type 'u32',
their product can wrap around and then be cast to 'u64'.
This can lead to two different XDP buffers pointing to the same
memory area.

Found by InfoTeCS on behalf of Linux Verification Center
(linuxtesting.org) with SVACE.

CREATE(Triage):(User=admin) CVE-2025-21997 (https://nvd.nist.gov/vuln/detail/CVE-2025-21997)

CVEs


Live chat
Online