In the Linux kernel, the following vulnerability has been resolved:
pktgen: Avoid out-of-bounds access in getimixentries
Passing a sufficient amount of imix entries leads to invalid access to the pktdev->imixentries array because of the incorrect boundary check.
UBSAN: array-index-out-of-bounds in net/core/pktgen.c:874:24 index 20 is out of range for type 'imixpkt [20]' CPU: 2 PID: 1210 Comm: bash Not tainted 6.10.0-rc1 #121 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996) Call Trace: <TASK> dumpstacklvl lib/dumpstack.c:117 __ubsanhandleoutofbounds lib/ubsan.c:429 getimixentries net/core/pktgen.c:874 pktgenifwrite net/core/pktgen.c:1063 pdewrite fs/proc/inode.c:334 procregwrite fs/proc/inode.c:346 vfswrite fs/readwrite.c:593 ksyswrite fs/readwrite.c:644 dosyscall64 arch/x86/entry/common.c:83 entrySYSCALL64afterhwframe arch/x86/entry/entry64.S:130
Found by Linux Verification Center (linuxtesting.org) with SVACE.
[ fp: allow to fill the array completely; minor changelog cleanup ]
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21680.json"
}[
{
"signature_type": "Function",
"deprecated": false,
"id": "CVE-2025-21680-ab27c6d0",
"target": {
"file": "net/core/pktgen.c",
"function": "get_imix_entries"
},
"digest": {
"length": 904.0,
"function_hash": "149933248569055053504962803067689602896"
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@76201b5979768500bca362871db66d77cb4c225e"
},
{
"signature_type": "Line",
"deprecated": false,
"id": "CVE-2025-21680-b5c661d6",
"target": {
"file": "net/core/pktgen.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"126572329826383604202336763920287098701",
"209002075773678557635129826950646784104",
"43663412143076591904823373450623580540",
"319626709824985042284392521908301588030",
"210985230768690092190587494200816069345",
"112357815921437827354209103211240816002",
"143667453037163833332413893323999610200",
"108022669389537604043241719942943481459"
]
},
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@76201b5979768500bca362871db66d77cb4c225e"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-21680.json"