CVE-2025-21785

Source
https://cve.org/CVERecord?id=CVE-2025-21785
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21785.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-21785
Downstream
Related
Published
2025-02-27T02:18:25.938Z
Modified
2026-03-20T12:41:10.409409Z
Summary
arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array
Details

In the Linux kernel, the following vulnerability has been resolved:

arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array

The loop that detects/populates cache information already has a bounds check on the array size but does not account for cache levels with separate data/instructions cache. Fix this by incrementing the index for any populated leaf (instead of any populated level).

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21785.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5d425c18653731af62831d30a4fa023d532657a9
Fixed
4371ac7b494e933fffee2bd6265d18d73c4f05aa
Fixed
e4fde33107351ec33f1a64188612fbc6ca659284
Fixed
88a3e6afaf002250220793df99404977d343db14
Fixed
4ff25f0b18d1d0174c105e4620428bcdc1213860
Fixed
ab90894f33c15b14c1cee6959ab6c8dcb09127f8
Fixed
715eb1af64779e1b1aa0a7b2ffb81414d9f708e5
Fixed
67b99a2b5811df4294c2ad50f9bff3b6a08bd618
Fixed
875d742cf5327c93cba1f11e12b08d3cce7a88d2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-21785.json"