Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: LoongArch: csum: Fix OoB access in IP checksum code for negative lengths Commit 69e3a6aa6be2 ("LoongArch: Add checksum optimization for 64-bit system") would cause an undefined shift and an out-of-bounds read. Commit 8bd795fedb84 ("arm64: csum: Fix OoB access in IP checksum code for negative lengths") fixes the same issue on ARM64.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 6.4, < 6.6.79 |
Related Weaknesses (CWE)
References
- https://git.kernel.org/stable/c/6287f1a8c16138c2ec750953e35039634018c84aMailing ListPatch
- https://git.kernel.org/stable/c/964a8895704a22efc06a2a3276b624a5ae985a06Mailing ListPatch
- https://git.kernel.org/stable/c/9f15a8df542c0f08732a67d1a14ee7c22948fb97Mailing ListPatch
- https://git.kernel.org/stable/c/d6508ffff32b44b6d0de06704034e4eef1c307a7Mailing ListPatch
FAQ
What is CVE-2025-21789?
CVE-2025-21789 is a vulnerability with a CVSS score of 7.1 (HIGH). In the Linux kernel, the following vulnerability has been resolved: LoongArch: csum: Fix OoB access in IP checksum code for negative lengths Commit 69e3a6aa6be2 ("LoongArch: Add checksum optimizatio...
How severe is CVE-2025-21789?
CVE-2025-21789 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-21789?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel.