CVE-2025-21785: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array The loop that detects/populates cache information already has a bounds check on the array size but does not account for cache levels with separate data/instructions cache. Fix this by incrementing the index for any populated leaf (instead of any populated level).

Affected products

  • Linux Linux Kernel: from 4.0, before 6.1.129 (fixed in 6.1.129); from 6.2, before 6.6.79 (fixed in 6.6.79); from 6.7, before 6.12.16 (fixed in 6.12.16); from 6.13, before 6.13.4 (fixed in 6.13.4); version 6.14 only

Published 2025-02-27. Last modified 2026-07-30.