Executive brief
A vulnerability was identified in the Linux kernel's memory management component used for device virtualization. A technical error in how the system calculates memory offsets could lead to unpredictable system behavior or crashes. This could potentially allow a local user with basic access to compromise the stability or security of the host system.
Technical details
A shift-out-of-bounds vulnerability exists in the iova_bitmap_offset_to_index() function within the iommufd/iova_bitmap component of the Linux kernel. The root cause is an integer overflow where a 32-bit integer constant '1' is shifted by a value (pgshift) that can exceed 31 bits, leading to undefined behavior. An attacker with local access could potentially exploit this to cause a kernel crash or achieve out-of-bounds memory access. The issue has been resolved by promoting the constant to an unsigned long (1UL) to accommodate larger shift values. Patches are available for multiple stable kernel branches including 6.1.y, 6.6.y, 6.12.y, and 6.13.y.
Affected products
- Linux Linux Kernel 6.1 to 6.1.129, 6.2 to 6.6.76, 6.7 to 6.12.13, 6.13 to 6.13.2
Timeline
- 2025-01-13: other: Patch authored
- 2025-02-26: advisory: NVD Published Date
- 2025-02-27: disclosed: Public disclosure of CVE-2025-21724
References
- https://git.kernel.org/stable/c/38ac76fc06bc6826a3e4b12a98efbe98432380a9
- https://git.kernel.org/stable/c/44d9c94b7a3f29a3e07c4753603a35e9b28842a3
- https://git.kernel.org/stable/c/b1f8453b8ff1ab79a03820ef608256c499769cb6
- https://git.kernel.org/stable/c/d5d33f01b86af44b23eea61ee309e4ef22c0cdfe
- https://git.kernel.org/stable/c/e24c1551059268b37f6f40639883eafb281b8b9c
- https://lists.debian.org/debian-lts-announce/2025/03/msg00028.html
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html