In the Linux kernel, the following vulnerability has been resolved:
misc: fastrpc: Fix copy buffer page size
For non-registered buffer, fastrpc driver copies the buffer and pass it to the remote subsystem. There is a problem with current implementation of page size calculation which is not considering the offset in the calculation. This might lead to passing of improper and out-of-bounds page size which could result in memory issue. Calculate page start and page end using the offset adjusted address instead of absolute address.
[
{
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c0464bad0e85fcd5d47e4297d1e410097c979e55",
"digest": {
"function_hash": "129958922204587856451839991370572364494",
"length": 3143.0
},
"id": "CVE-2025-21734-03bb4030",
"signature_type": "Function",
"target": {
"function": "fastrpc_get_args",
"file": "drivers/misc/fastrpc.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e966eae72762ecfdbdb82627e2cda48845b9dd66",
"digest": {
"threshold": 0.9,
"line_hashes": [
"71677373487984469813563895316949473956",
"269367094232164833170863511097425263901",
"270060527759474779727083034810651358452",
"149145067993314728608237481695388958715",
"107043006364169981400454880256857097032"
]
},
"id": "CVE-2025-21734-332ecdff",
"signature_type": "Line",
"target": {
"file": "drivers/misc/fastrpc.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c0464bad0e85fcd5d47e4297d1e410097c979e55",
"digest": {
"threshold": 0.9,
"line_hashes": [
"71677373487984469813563895316949473956",
"269367094232164833170863511097425263901",
"270060527759474779727083034810651358452",
"149145067993314728608237481695388958715",
"107043006364169981400454880256857097032"
]
},
"id": "CVE-2025-21734-3ded3e08",
"signature_type": "Line",
"target": {
"file": "drivers/misc/fastrpc.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e966eae72762ecfdbdb82627e2cda48845b9dd66",
"digest": {
"function_hash": "24828008500500519973720995096727795763",
"length": 3244.0
},
"id": "CVE-2025-21734-3e3c7504",
"signature_type": "Function",
"target": {
"function": "fastrpc_get_args",
"file": "drivers/misc/fastrpc.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@24a79c6bc8de763f7c50f4f84f8b0c183bc25a51",
"digest": {
"threshold": 0.9,
"line_hashes": [
"71677373487984469813563895316949473956",
"269367094232164833170863511097425263901",
"270060527759474779727083034810651358452",
"149145067993314728608237481695388958715",
"107043006364169981400454880256857097032"
]
},
"id": "CVE-2025-21734-a791a5bf",
"signature_type": "Line",
"target": {
"file": "drivers/misc/fastrpc.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@24a79c6bc8de763f7c50f4f84f8b0c183bc25a51",
"digest": {
"function_hash": "24828008500500519973720995096727795763",
"length": 3244.0
},
"id": "CVE-2025-21734-ac2b6b86",
"signature_type": "Function",
"target": {
"function": "fastrpc_get_args",
"file": "drivers/misc/fastrpc.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c56ba3ea8e3c9a69a992aad18f7a65e43e51d623",
"digest": {
"threshold": 0.9,
"line_hashes": [
"71677373487984469813563895316949473956",
"269367094232164833170863511097425263901",
"270060527759474779727083034810651358452",
"149145067993314728608237481695388958715",
"107043006364169981400454880256857097032"
]
},
"id": "CVE-2025-21734-b8d840c5",
"signature_type": "Line",
"target": {
"file": "drivers/misc/fastrpc.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c56ba3ea8e3c9a69a992aad18f7a65e43e51d623",
"digest": {
"function_hash": "129958922204587856451839991370572364494",
"length": 3143.0
},
"id": "CVE-2025-21734-d5ad1ce4",
"signature_type": "Function",
"target": {
"function": "fastrpc_get_args",
"file": "drivers/misc/fastrpc.c"
}
}
]