CVE-2025-22107: net: dsa: sja1105: fix kasan out-of-bounds warning in sja1105_table_delete_entry()
In the Linux kernel, the following vulnerability has been resolved:
net: dsa: sja1105: fix kasan out-of-bounds warning in sja1105tabledeleteentry()
There are actually 2 problems: - deleting the last element doesn't require the memmove of elements [i + 1, end) over it. Actually, element i+1 is out of bounds. - The memmove itself should move size - i - 1 elements, because the last element is out of bounds.
The out-of-bounds element still remains out of bounds after being accessed, so the problem is only that we touch it, not that it becomes in active use. But I suppose it can lead to issues if the out-of-bounds element is part of an unmapped page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.121.1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22107?
CVE-2025-22107 has a medium severity due to potential out-of-bounds access issues in the Linux kernel.
How do I fix CVE-2025-22107?
To fix CVE-2025-22107, update the Linux kernel to the latest version where this vulnerability has been patched.
What versions of the Linux kernel are affected by CVE-2025-22107?
CVE-2025-22107 affects multiple versions of the Linux kernel prior to the issuance of the patch.
What impact does CVE-2025-22107 have on the Linux kernel?
CVE-2025-22107 can lead to potential memory corruption by allowing out-of-bounds access in specific network operations.
Is CVE-2025-22107 publicly known?
Yes, CVE-2025-22107 is a publicly known vulnerability as part of the Linux kernel security advisories.