2025-02-27 05:03:48 +00:00
|
|
|
{
|
|
|
|
"id": "CVE-2025-21787",
|
|
|
|
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
|
|
|
|
"published": "2025-02-27T03:15:19.553",
|
2025-03-13 15:03:52 +00:00
|
|
|
"lastModified": "2025-03-13T13:15:54.840",
|
|
|
|
"vulnStatus": "Modified",
|
2025-02-27 05:03:48 +00:00
|
|
|
"cveTags": [],
|
|
|
|
"descriptions": [
|
|
|
|
{
|
|
|
|
"lang": "en",
|
|
|
|
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nteam: better TEAM_OPTION_TYPE_STRING validation\n\nsyzbot reported following splat [1]\n\nMake sure user-provided data contains one nul byte.\n\n[1]\n BUG: KMSAN: uninit-value in string_nocheck lib/vsprintf.c:633 [inline]\n BUG: KMSAN: uninit-value in string+0x3ec/0x5f0 lib/vsprintf.c:714\n string_nocheck lib/vsprintf.c:633 [inline]\n string+0x3ec/0x5f0 lib/vsprintf.c:714\n vsnprintf+0xa5d/0x1960 lib/vsprintf.c:2843\n __request_module+0x252/0x9f0 kernel/module/kmod.c:149\n team_mode_get drivers/net/team/team_core.c:480 [inline]\n team_change_mode drivers/net/team/team_core.c:607 [inline]\n team_mode_option_set+0x437/0x970 drivers/net/team/team_core.c:1401\n team_option_set drivers/net/team/team_core.c:375 [inline]\n team_nl_options_set_doit+0x1339/0x1f90 drivers/net/team/team_core.c:2662\n genl_family_rcv_msg_doit net/netlink/genetlink.c:1115 [inline]\n genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline]\n genl_rcv_msg+0x1214/0x12c0 net/netlink/genetlink.c:1210\n netlink_rcv_skb+0x375/0x650 net/netlink/af_netlink.c:2543\n genl_rcv+0x40/0x60 net/netlink/genetlink.c:1219\n netlink_unicast_kernel net/netlink/af_netlink.c:1322 [inline]\n netlink_unicast+0xf52/0x1260 net/netlink/af_netlink.c:1348\n netlink_sendmsg+0x10da/0x11e0 net/netlink/af_netlink.c:1892\n sock_sendmsg_nosec net/socket.c:718 [inline]\n __sock_sendmsg+0x30f/0x380 net/socket.c:733\n ____sys_sendmsg+0x877/0xb60 net/socket.c:2573\n ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2627\n __sys_sendmsg net/socket.c:2659 [inline]\n __do_sys_sendmsg net/socket.c:2664 [inline]\n __se_sys_sendmsg net/socket.c:2662 [inline]\n __x64_sys_sendmsg+0x212/0x3c0 net/socket.c:2662\n x64_sys_call+0x2ed6/0x3c30 arch/x86/include/generated/asm/syscalls_64.h:47\n do_syscall_x64 arch/x86/entry/common.c:52 [inline]\n do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83\n entry_SYSCALL_64_after_hwframe+0x77/0x7f"
|
2025-03-02 03:03:52 +00:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"lang": "es",
|
|
|
|
"value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: equipo: mejor validaci\u00f3n de TEAM_OPTION_TYPE_STRING syzbot inform\u00f3 lo siguiente: [1] Aseg\u00farese de que los datos proporcionados por el usuario contengan un byte nulo. [1] ERROR: KMSAN: valor no inicializado en string_nocheck lib/vsprintf.c:633 [en l\u00ednea] ERROR: KMSAN: valor no inicializado en string+0x3ec/0x5f0 lib/vsprintf.c:714 string_nocheck lib/vsprintf.c:633 [inline] string+0x3ec/0x5f0 lib/vsprintf.c:714 vsnprintf+0xa5d/0x1960 lib/vsprintf.c:2843 __request_module+0x252/0x9f0 kernel/module/kmod.c:149 team_mode_get drivers/net/team/team_core.c:480 [inline] team_change_mode drivers/net/team/team_core.c:607 [inline] team_mode_option_set+0x437/0x970 drivers/net/team/team_core.c:1401 team_option_set drivers/net/team/team_core.c:375 [inline] team_nl_options_set_doit+0x1339/0x1f90 drivers/net/team/team_core.c:2662 genl_family_rcv_msg_doit net/netlink/genetlink.c:1115 [inline] genl_family_rcv_msg net/netlink/genetlink.c:1195 [inline] genl_rcv_msg+0x1214/0x12c0 net/netlink/genetlink.c:1210 netlink_rcv_skb+0x375/0x650 net/netlink/af_netlink.c:2543 genl_rcv+0x40/0x60 net/netlink/genetlink.c:1219 netlink_unicast_kernel net/netlink/af_netlink.c:1322 [inline] netlink_unicast+0xf52/0x1260 net/netlink/af_netlink.c:1348 netlink_sendmsg+0x10da/0x11e0 net/netlink/af_netlink.c:1892 sock_sendmsg_nosec net/socket.c:718 [inline] __sock_sendmsg+0x30f/0x380 net/socket.c:733 ____sys_sendmsg+0x877/0xb60 net/socket.c:2573 ___sys_sendmsg+0x28d/0x3c0 net/socket.c:2627 __sys_sendmsg net/socket.c:2659 [inline] __do_sys_sendmsg net/socket.c:2664 [inline] __se_sys_sendmsg net/socket.c:2662 [inline] __x64_sys_sendmsg+0x212/0x3c0 net/socket.c:2662 x64_sys_call+0x2ed6/0x3c30 arch/x86/include/generated/asm/syscalls_64.h:47 do_syscall_x64 arch/x86/entry/common.c:52 [inline] do_syscall_64+0xcd/0x1e0 arch/x86/entry/common.c:83 entry_SYSCALL_64_after_hwframe+0x77/0x7f"
|
2025-02-27 05:03:48 +00:00
|
|
|
}
|
|
|
|
],
|
2025-03-09 03:03:50 +00:00
|
|
|
"metrics": {
|
|
|
|
"cvssMetricV31": [
|
|
|
|
{
|
|
|
|
"source": "nvd@nist.gov",
|
|
|
|
"type": "Primary",
|
|
|
|
"cvssData": {
|
|
|
|
"version": "3.1",
|
|
|
|
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
|
|
|
|
"baseScore": 5.5,
|
|
|
|
"baseSeverity": "MEDIUM",
|
|
|
|
"attackVector": "LOCAL",
|
|
|
|
"attackComplexity": "LOW",
|
|
|
|
"privilegesRequired": "LOW",
|
|
|
|
"userInteraction": "NONE",
|
|
|
|
"scope": "UNCHANGED",
|
|
|
|
"confidentialityImpact": "NONE",
|
|
|
|
"integrityImpact": "NONE",
|
|
|
|
"availabilityImpact": "HIGH"
|
|
|
|
},
|
|
|
|
"exploitabilityScore": 1.8,
|
|
|
|
"impactScore": 3.6
|
|
|
|
}
|
|
|
|
]
|
|
|
|
},
|
|
|
|
"weaknesses": [
|
|
|
|
{
|
|
|
|
"source": "nvd@nist.gov",
|
|
|
|
"type": "Secondary",
|
|
|
|
"description": [
|
|
|
|
{
|
|
|
|
"lang": "en",
|
|
|
|
"value": "CWE-908"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"configurations": [
|
|
|
|
{
|
|
|
|
"nodes": [
|
|
|
|
{
|
|
|
|
"operator": "OR",
|
|
|
|
"negate": false,
|
|
|
|
"cpeMatch": [
|
|
|
|
{
|
|
|
|
"vulnerable": true,
|
|
|
|
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
|
|
|
|
"versionStartIncluding": "3.3",
|
|
|
|
"versionEndExcluding": "6.1.129",
|
|
|
|
"matchCriteriaId": "E9C14B40-B889-4BBF-A766-22C54E3B7BFF"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"vulnerable": true,
|
|
|
|
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
|
|
|
|
"versionStartIncluding": "6.2",
|
|
|
|
"versionEndExcluding": "6.6.79",
|
|
|
|
"matchCriteriaId": "B16AADE5-B2FD-4C14-B4E4-85E8EDAFE775"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"vulnerable": true,
|
|
|
|
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
|
|
|
|
"versionStartIncluding": "6.7",
|
|
|
|
"versionEndExcluding": "6.12.16",
|
|
|
|
"matchCriteriaId": "13C8DB18-FC60-425F-84E5-3EDDEC61B2FC"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"vulnerable": true,
|
|
|
|
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
|
|
|
|
"versionStartIncluding": "6.13",
|
|
|
|
"versionEndExcluding": "6.13.4",
|
|
|
|
"matchCriteriaId": "2A2093ED-74A9-43F9-AC72-50030F374EA4"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"vulnerable": true,
|
|
|
|
"criteria": "cpe:2.3:o:linux:linux_kernel:6.14:rc1:*:*:*:*:*:*",
|
|
|
|
"matchCriteriaId": "186716B6-2B66-4BD0-852E-D48E71C0C85F"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"vulnerable": true,
|
|
|
|
"criteria": "cpe:2.3:o:linux:linux_kernel:6.14:rc2:*:*:*:*:*:*",
|
|
|
|
"matchCriteriaId": "0D3E781C-403A-498F-9DA9-ECEE50F41E75"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
],
|
2025-02-27 05:03:48 +00:00
|
|
|
"references": [
|
|
|
|
{
|
|
|
|
"url": "https://git.kernel.org/stable/c/4236bf4716589558cc0f3c3612642b2c2141b04e",
|
2025-03-09 03:03:50 +00:00
|
|
|
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
|
|
|
|
"tags": [
|
2025-03-13 15:03:52 +00:00
|
|
|
"Mailing List",
|
|
|
|
"Patch"
|
2025-03-09 03:03:50 +00:00
|
|
|
]
|
2025-02-27 05:03:48 +00:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"url": "https://git.kernel.org/stable/c/4512482e4805dd30bc77dec511f2a2edba5cb868",
|
2025-03-09 03:03:50 +00:00
|
|
|
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
|
|
|
|
"tags": [
|
2025-03-13 15:03:52 +00:00
|
|
|
"Mailing List",
|
|
|
|
"Patch"
|
2025-03-09 03:03:50 +00:00
|
|
|
]
|
2025-02-27 05:03:48 +00:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"url": "https://git.kernel.org/stable/c/5bef3ac184b5626ea62385d6b82a1992b89d7940",
|
2025-03-09 03:03:50 +00:00
|
|
|
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
|
|
|
|
"tags": [
|
2025-03-13 15:03:52 +00:00
|
|
|
"Mailing List",
|
|
|
|
"Patch"
|
2025-03-09 03:03:50 +00:00
|
|
|
]
|
2025-02-27 05:03:48 +00:00
|
|
|
},
|
2025-03-13 15:03:52 +00:00
|
|
|
{
|
|
|
|
"url": "https://git.kernel.org/stable/c/7c30483d0f6bdb2230e10e3e4be5167927eac7a0",
|
|
|
|
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"url": "https://git.kernel.org/stable/c/7f5af50f3aa0af8cbef9fb76fffeed69e8143f59",
|
|
|
|
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
|
|
|
|
},
|
2025-02-27 05:03:48 +00:00
|
|
|
{
|
|
|
|
"url": "https://git.kernel.org/stable/c/8401cade1918281177974b32c925afdce750d292",
|
2025-03-09 03:03:50 +00:00
|
|
|
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
|
|
|
|
"tags": [
|
2025-03-13 15:03:52 +00:00
|
|
|
"Mailing List",
|
|
|
|
"Patch"
|
2025-03-09 03:03:50 +00:00
|
|
|
]
|
2025-02-27 05:03:48 +00:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"url": "https://git.kernel.org/stable/c/d071a91fa614ecdf760c29f61f6a7bfb7df796d6",
|
2025-03-09 03:03:50 +00:00
|
|
|
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
|
|
|
|
"tags": [
|
2025-03-13 15:03:52 +00:00
|
|
|
"Mailing List",
|
|
|
|
"Patch"
|
2025-03-09 03:03:50 +00:00
|
|
|
]
|
2025-03-13 15:03:52 +00:00
|
|
|
},
|
|
|
|
{
|
|
|
|
"url": "https://git.kernel.org/stable/c/f443687ad20c70320d1248f35f57bf46cac8df0a",
|
|
|
|
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
|
2025-02-27 05:03:48 +00:00
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|