Answer in brief
CVE-2025-21687 records a Unknown severity vulnerability in vfio/platform: check the bounds of read/write syscalls. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-21687 records a Unknown severity vulnerability in vfio/platform: check the bounds of read/write syscalls. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6e3f264560099869f68830cb14b3b3e71e5ac76a <f21636f24b6786c8b13f1af4319fa75ffcf17f38 || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <9377cdc118cf327248f1a9dde7b87de067681dc9 || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <d19a8650fd3d7aed8d1af1d9a77f979a8430eba1 || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <ed81d82bb6e9df3a137f2c343ed689e6c68268ef || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <92340e6c5122d823ad064984ef7513eba9204048 || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <f65ce06387f8c1fb54bd59e18a8428248ec68eaf || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <6bcb8a5b70b80143db9bf12dfa7d53636f824d53 || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <1485932496a1b025235af8aa1e21988d6b7ccd54 || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <c981c32c38af80737a2fedc16e270546d139ccdd || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <a20fcaa230f7472456d12cf761ed13938e320ac3 || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <665cfd1083866f87301bbd232cb8ba48dcf4acce || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <ce9ff21ea89d191e477a02ad7eabf4f996b80a69 | f21636f24b6786c8b13f1af4319fa75ffcf17f38, 9377cdc118cf327248f1a9dde7b87de067681dc9, d19a8650fd3d7aed8d1af1d9a77f979a8430eba1, ed81d82bb6e9df3a137f2c343ed689e6c68268ef, 92340e6c5122d823ad064984ef7513eba9204048, f65ce06387f8c1fb54bd59e18a8428248ec68eaf, 6bcb8a5b70b80143db9bf12dfa7d53636f824d53, 1485932496a1b025235af8aa1e21988d6b7ccd54, c981c32c38af80737a2fedc16e270546d139ccdd, a20fcaa230f7472456d12cf761ed13938e320ac3, 665cfd1083866f87301bbd232cb8ba48dcf4acce, ce9ff21ea89d191e477a02ad7eabf4f996b80a69 |
| Linux/Linuxgeneric | 4.1 | Not reported |
Published upstream
Feb 10, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write syscalls count and offset are passed from user space and not checked, only offset is capped to 40 bits, which can be used to read/write out of bounds of the device.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=6e3f264560099869f68830cb14b3b3e71e5ac76a <f21636f24b6786c8b13f1af4319fa75ffcf17f38 || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <9377cdc118cf327248f1a9dde7b87de067681dc9 || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <d19a8650fd3d7aed8d1af1d9a77f979a8430eba1 || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <ed81d82bb6e9df3a137f2c343ed689e6c68268ef || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <92340e6c5122d823ad064984ef7513eba9204048 || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <f65ce06387f8c1fb54bd59e18a8428248ec68eaf || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <6bcb8a5b70b80143db9bf12dfa7d53636f824d53 || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <1485932496a1b025235af8aa1e21988d6b7ccd54 || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <c981c32c38af80737a2fedc16e270546d139ccdd || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <a20fcaa230f7472456d12cf761ed13938e320ac3 || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <665cfd1083866f87301bbd232cb8ba48dcf4acce || >=6e3f264560099869f68830cb14b3b3e71e5ac76a <ce9ff21ea89d191e477a02ad7eabf4f996b80a69 | f21636f24b6786c8b13f1af4319fa75ffcf17f38, 9377cdc118cf327248f1a9dde7b87de067681dc9, d19a8650fd3d7aed8d1af1d9a77f979a8430eba1, ed81d82bb6e9df3a137f2c343ed689e6c68268ef, 92340e6c5122d823ad064984ef7513eba9204048, f65ce06387f8c1fb54bd59e18a8428248ec68eaf, 6bcb8a5b70b80143db9bf12dfa7d53636f824d53, 1485932496a1b025235af8aa1e21988d6b7ccd54, c981c32c38af80737a2fedc16e270546d139ccdd, a20fcaa230f7472456d12cf761ed13938e320ac3, 665cfd1083866f87301bbd232cb8ba48dcf4acce, ce9ff21ea89d191e477a02ad7eabf4f996b80a69 |
| Linux/Linuxgeneric | 4.1 | Not reported |
Published upstream
Feb 10, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write syscalls count and offset are passed from user space and not checked, only offset is capped to 40 bits, which can be used to read/write out of bounds of the device.
Quoted source text, attributed separately from HOL analysis.