目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-21707— Linux kernel 安全漏洞

CVSS 9.8 · Critical EPSS 0.47% · P38

Affected Version Matrix 14

ベンダープロダクトVersion Rangeステータス
LinuxLinux84dfe3677a6f45b3d0dfdd564e55717a1a5e60cc< 3a7fda57b0f91f7ea34476b165f91a92feb17c96affected
84dfe3677a6f45b3d0dfdd564e55717a1a5e60cc< 3b5332d416d151a15742d1b16e7319368e3cc5c6affected
84dfe3677a6f45b3d0dfdd564e55717a1a5e60cc< 7f6c72b8ef8130760710e337dc8fbe7263954884affected
84dfe3677a6f45b3d0dfdd564e55717a1a5e60cc< 6169e942370b4b6f9442d35c51519bf6c346843baffected
84dfe3677a6f45b3d0dfdd564e55717a1a5e60cc< ba0518f9e8688cd4fcb569e8df2a74874b4f3894affected
84dfe3677a6f45b3d0dfdd564e55717a1a5e60cc< c86b000782daba926c627d2fa00c3f60a75e7472affected
5.11affected
< 5.11unaffected
… +6 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-21707の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
mptcp: consolidate suboption status
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: mptcp: consolidate suboption status MPTCP maintains the received sub-options status is the bitmask carrying the received suboptions and in several bitfields carrying per suboption additional info. Zeroing the bitmask before parsing is not enough to ensure a consistent status, and the MPTCP code has to additionally clear some bitfiled depending on the actually parsed suboption. The above schema is fragile, and syzbot managed to trigger a path where a relevant bitfield is not cleared/initialized: BUG: KMSAN: uninit-value in __mptcp_expand_seq net/mptcp/options.c:1030 [inline] BUG: KMSAN: uninit-value in mptcp_expand_seq net/mptcp/protocol.h:864 [inline] BUG: KMSAN: uninit-value in ack_update_msk net/mptcp/options.c:1060 [inline] BUG: KMSAN: uninit-value in mptcp_incoming_options+0x2036/0x3d30 net/mptcp/options.c:1209 __mptcp_expand_seq net/mptcp/options.c:1030 [inline] mptcp_expand_seq net/mptcp/protocol.h:864 [inline] ack_update_msk net/mptcp/options.c:1060 [inline] mptcp_incoming_options+0x2036/0x3d30 net/mptcp/options.c:1209 tcp_data_queue+0xb4/0x7be0 net/ipv4/tcp_input.c:5233 tcp_rcv_established+0x1061/0x2510 net/ipv4/tcp_input.c:6264 tcp_v4_do_rcv+0x7f3/0x11a0 net/ipv4/tcp_ipv4.c:1916 tcp_v4_rcv+0x51df/0x5750 net/ipv4/tcp_ipv4.c:2351 ip_protocol_deliver_rcu+0x2a3/0x13d0 net/ipv4/ip_input.c:205 ip_local_deliver_finish+0x336/0x500 net/ipv4/ip_input.c:233 NF_HOOK include/linux/netfilter.h:314 [inline] ip_local_deliver+0x21f/0x490 net/ipv4/ip_input.c:254 dst_input include/net/dst.h:460 [inline] ip_rcv_finish+0x4a2/0x520 net/ipv4/ip_input.c:447 NF_HOOK include/linux/netfilter.h:314 [inline] ip_rcv+0xcd/0x380 net/ipv4/ip_input.c:567 __netif_receive_skb_one_core net/core/dev.c:5704 [inline] __netif_receive_skb+0x319/0xa00 net/core/dev.c:5817 process_backlog+0x4ad/0xa50 net/core/dev.c:6149 __napi_poll+0xe7/0x980 net/core/dev.c:6902 napi_poll net/core/dev.c:6971 [inline] net_rx_action+0xa5a/0x19b0 net/core/dev.c:7093 handle_softirqs+0x1a0/0x7c0 kernel/softirq.c:561 __do_softirq+0x14/0x1a kernel/softirq.c:595 do_softirq+0x9a/0x100 kernel/softirq.c:462 __local_bh_enable_ip+0x9f/0xb0 kernel/softirq.c:389 local_bh_enable include/linux/bottom_half.h:33 [inline] rcu_read_unlock_bh include/linux/rcupdate.h:919 [inline] __dev_queue_xmit+0x2758/0x57d0 net/core/dev.c:4493 dev_queue_xmit include/linux/netdevice.h:3168 [inline] neigh_hh_output include/net/neighbour.h:523 [inline] neigh_output include/net/neighbour.h:537 [inline] ip_finish_output2+0x187c/0x1b70 net/ipv4/ip_output.c:236 __ip_finish_output+0x287/0x810 ip_finish_output+0x4b/0x600 net/ipv4/ip_output.c:324 NF_HOOK_COND include/linux/netfilter.h:303 [inline] ip_output+0x15f/0x3f0 net/ipv4/ip_output.c:434 dst_output include/net/dst.h:450 [inline] ip_local_out net/ipv4/ip_output.c:130 [inline] __ip_queue_xmit+0x1f2a/0x20d0 net/ipv4/ip_output.c:536 ip_queue_xmit+0x60/0x80 net/ipv4/ip_output.c:550 __tcp_transmit_skb+0x3cea/0x4900 net/ipv4/tcp_output.c:1468 tcp_transmit_skb net/ipv4/tcp_output.c:1486 [inline] tcp_write_xmit+0x3b90/0x9070 net/ipv4/tcp_output.c:2829 __tcp_push_pending_frames+0xc4/0x380 net/ipv4/tcp_output.c:3012 tcp_send_fin+0x9f6/0xf50 net/ipv4/tcp_output.c:3618 __tcp_close+0x140c/0x1550 net/ipv4/tcp.c:3130 __mptcp_close_ssk+0x74e/0x16f0 net/mptcp/protocol.c:2496 mptcp_close_ssk+0x26b/0x2c0 net/mptcp/protocol.c:2550 mptcp_pm_nl_rm_addr_or_subflow+0x635/0xd10 net/mptcp/pm_netlink.c:889 mptcp_pm_nl_rm_subflow_received net/mptcp/pm_netlink.c:924 [inline] mptcp_pm_flush_addrs_and_subflows net/mptcp/pm_netlink.c:1688 [inline] mptcp_nl_flush_addrs_list net/mptcp/pm_netlink.c:1709 [inline] mptcp_pm_nl_flush_addrs_doit+0xe10/0x1630 net/mptcp/pm_netlink.c:1750 genl_family_rcv_msg_doit net/netlink/genetlink.c:1115 [inline] ---truncated---
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于mptcp子选项状态未正确初始化。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 84dfe3677a6f45b3d0dfdd564e55717a1a5e60cc ~ 3a7fda57b0f91f7ea34476b165f91a92feb17c96 -
LinuxLinux 5.11 -

II. CVE-2025-21707の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-21707のインテリジェンス情報

登录查看更多情报信息。

CVE-2025-21707 补丁与修复 (5)

CVE-2025-21707 其他参考 (1)

Same Patch Batch · Linux · 2025-02-27 · 177 CVEs total

CVE-2025-218059.8 CRITICALRDMA/rtrs: Add missing deinit() call
CVE-2025-217489.8 CRITICALksmbd: fix integer overflows on 32 bit systems
CVE-2025-217969.8 CRITICALnfsd: clear acl_access/acl_default after releasing them
CVE-2025-217358.8 HIGHNFC: nci: Add bounds checking in nci_hci_create_pipe()
CVE-2025-217108.2 HIGHtcp: correct handling of extreme memory squeeze
CVE-2025-217628.1 HIGHarp: use RCU protection in arp_xmit()
CVE-2025-217608.1 HIGHndisc: extend RCU protection in ndisc_send_skb()
CVE-2025-217658.1 HIGHipv6: use RCU protection in ip6_default_advmss()
CVE-2025-217668.1 HIGHipv4: use RCU protection in __ip_rt_update_pmtu()
CVE-2025-217147.8 HIGHRDMA/mlx5: Fix implicit ODP use after free
CVE-2025-217387.8 HIGHata: libata-sff: Ensure that we cannot write outside the allocated buffer
CVE-2025-217097.8 HIGHkernel: be more careful about dup_mmap() failures and uprobe registering
CVE-2025-217127.8 HIGHmd/md-bitmap: Synchronize bitmap_get_stats() with bitmap lifetime
CVE-2025-217347.8 HIGHmisc: fastrpc: Fix copy buffer page size
CVE-2025-217307.8 HIGHwifi: rtw89: avoid to init mgnt_entry list twice when WoWLAN failed
CVE-2025-217277.8 HIGHpadata: fix UAF in padata_reorder
CVE-2025-217297.8 HIGHwifi: rtw89: fix race between cancel_hw_scan and hw_scan completion
CVE-2025-217267.8 HIGHpadata: avoid UAF for reorder_work
CVE-2025-217857.8 HIGHarm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array
CVE-2025-217867.8 HIGHworkqueue: Put the pwq after detaching the rescuer from the pool

Showing 20 of 177 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2025-21707へのコメント

まだコメントはありません


コメントを残す