CVE-2025-21782

high

Description

In the Linux kernel, the following vulnerability has been resolved: orangefs: fix a oob in orangefs_debug_write I got a syzbot report: slab-out-of-bounds Read in orangefs_debug_write... several people suggested fixes, I tested Al Viro's suggestion and made this patch.

References

https://git.kernel.org/stable/c/f7c848431632598ff9bce57a659db6af60d75b39

https://git.kernel.org/stable/c/897f496b946fdcfab5983c983e4b513ab6682364

https://git.kernel.org/stable/c/2b84a231910cef2e0a16d29294afabfb69112087

https://git.kernel.org/stable/c/1da2697307dad281dd690a19441b5ca4af92d786

https://git.kernel.org/stable/c/1c5244299241cf49d8ae7b5054e299cc8faa4e09

Details

Source: Mitre, NVD

Published: 2025-02-27

Updated: 2025-02-27

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High