CVE-2025-22104

Source
https://cve.org/CVERecord?id=CVE-2025-22104
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-22104.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-22104
Downstream
Related
Published
2025-04-16T14:12:53.118Z
Modified
2026-09-04T03:30:17.158136272Z
Summary
ibmvnic: Use kernel helpers for hex dumps
Details

In the Linux kernel, the following vulnerability has been resolved:

ibmvnic: Use kernel helpers for hex dumps

Previously, when the driver was printing hex dumps, the buffer was cast to an 8 byte long and printed using string formatters. If the buffer size was not a multiple of 8 then a read buffer overflow was possible.

Therefore, create a new ibmvnic function that loops over a buffer and calls hexdumpto_buffer instead.

This patch address KASAN reports like the one below: ibmvnic 30000003 env3: Login Buffer: ibmvnic 30000003 env3: 01000000af000000 <...> ibmvnic 30000003 env3: 2e6d62692e736261 ibmvnic 30000003 env3: 65050003006d6f63 ================================================================== BUG: KASAN: slab-out-of-bounds in ibmvniclogin+0xacc/0xffc [ibmvnic] Read of size 8 at addr c0000001331a9aa8 by task ip/17681 <...> Allocated by task 17681: <...> ibmvniclogin+0x2f0/0xffc [ibmvnic] ibmvnic_open+0x148/0x308 [ibmvnic] _devopen+0x1ac/0x304 <...> The buggy address is located 168 bytes inside of allocated 175-byte region [c0000001331a9a00, c0000001331a9aaf) <...> ================================================================= ibmvnic 30000003 env3: 000000000033766e

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/22xxx/CVE-2025-22104.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
032c5e82847a2214c3196a90f0aeba0ce252de58
Fixed
19efa170e01207c8ada726f3f6c65b31fcba2a73
Fixed
9bc078818ec76344c2e06b81d7aee2df3adecfbf
Fixed
005fee039dd845122d313ac8f2122b0d09dc5d7b
Fixed
ae6b1d6c1acee3a2000394d83ec9f1028321e207
Fixed
d93a6caab5d7d9b5ce034d75b1e1e993338e3852

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-22104.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.5.0
Fixed
6.1.187
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.156
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.108
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.14.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-22104.json"