CVE-2025-21772: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: partitions: mac: fix handling of bogus partition table Fix several issues in partition probing: - The bailout for a bad partoffset must use put_dev_sector(), since the preceding read_part_sector() succeeded. - If the partition table claims a silly sector size like 0xfff bytes (which results in partition table entries straddling sector boundaries), bail out instead of accessing out-of-bounds memory. - We must not assume that the partition table contains proper NUL termination - use strnlen() and strncmp() instead of strlen() and strcmp().
Affected products
- Linux Linux Kernel: before 5.4.291 (fixed in 5.4.291); from 5.5, before 5.10.235 (fixed in 5.10.235); from 5.11, before 5.15.179 (fixed in 5.15.179); from 5.16, before 6.1.129 (fixed in 6.1.129); from 6.2, before 6.6.79 (fixed in 6.6.79); from 6.7, before 6.12.16 (fixed in 6.12.16); …
Published 2025-02-27. Last modified 2026-07-30.