PT-2025-4331 · Linux+4 · Linux Kernel+4

Hao Lan

+1

·

Published

2025-01-06

·

Updated

2025-10-03

·

CVE-2025-21650

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to an out-of-bounds access in the Linux kernel HNS3. The TQP BAR space is divided into two segments, but the hclge fetch pf reg function does not distinguish between these segments when reading the TQP space information. This can cause access bar space overwriting when the number of TQPs is greater than 1024. The problem has been considered during the initialization of tqp.io base, and tqp.io base is directly used when the queue is read in hclge fetch pf reg. An error message is generated when the kernel is unable to handle a paging request at a virtual address.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-12647
BDU:2025-04377
CVE-2025-21650
OESA-2025-1246
OESA-2025-1247
OESA-2025-1248
OPENSUSE-SU-2025_0428-1
OPENSUSE-SU-2025_0499-1
OPENSUSE-SU-2025_0557-1
SUSE-SU-2025:0289-1
SUSE-SU-2025:0428-1
SUSE-SU-2025:0499-1
SUSE-SU-2025:0557-1
SUSE-SU-2025:20165-1
SUSE-SU-2025:20166-1
SUSE-SU-2025:20248-1
SUSE-SU-2025:20249-1
SUSE-SU-2025_0428-1
SUSE-SU-2025_0499-1
SUSE-SU-2025_0557-1
USN-7379-1
USN-7379-2
USN-7380-1
USN-7381-1
USN-7382-1
USN-7513-1
USN-7513-2
USN-7513-3
USN-7513-4
USN-7513-5
USN-7514-1
USN-7515-1
USN-7515-2
USN-7522-1
USN-7523-1
USN-7524-1

Affected Products

Alt Linux
Linuxmint
Linux Kernel
Suse
Ubuntu