Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nikita Zhandarovich

#45155of 53,638
5.5Total CVSS
Vulnerabilities · 1
PT-2025-8794
5.5
2025-01-15
Linux · Linux Kernel · CVE-2025-21711
**Name of the Vulnerable Software and Affected Versions** Linux kernel (affected versions not specified) **Description** The issue concerns integer overflows in the `rose setsockopt()` function, which can occur when large arguments are passed and multiplied by additional values. This is addressed by checking the contents of the `opt` variable and returning an error if the values are too large. The fix also involves switching to unsigned int and removing an unnecessary check for negative `opt` values in the ROSE IDLE case. **Recommendations** For the affected Linux kernel versions, apply the fix by implementing the checks for the `opt` variable in the `rose setsockopt()` function and switch to unsigned int to prevent integer overflows. As a temporary workaround, consider restricting the use of the `rose setsockopt()` function until the issue is fully resolved.