CVE-2025-21738: ata: libata-sff: Ensure that we cannot write outside the allocated buffer
Published Feb 27, 2025
·Updated
ata: libata-sff: Ensure that we cannot write outside the allocated buffer
Affected Software
10 affected components
Linux Linux kernel
Linux Linux kernel<6.1.129
Linux Linux kernel>=6.2<6.6.78
Linux Linux kernel>=6.7<6.12.14
Linux Linux kernel>=6.13<6.13.3
Microsoft cbl2 kernel 5.15.186.1-1
IBM Verify Identity Access<=11.0 - 11.0.2
IBM Security Verify Access<=10.0 - 10.0.9.1
IBM Verify Identity Access Container<=11.0 - 11.0.2
IBM Security Verify Access Container<=10.0 - 10.0.9.1
Event History
Feb 27, 2025
CVE Published
via MITRE·02:12 AM
Data Sourced
via MITRE·02:12 AM
Description
Data Sourced
via Red Hat·03:04 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityAffected Software
Oct 30, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·01:01 AM
Affected Software
Updated
via Microsoft·01:01 AM
DescriptionSeverity
Jul 8, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-21738?
CVE-2025-21738 is classified with moderate severity due to potential buffer overflow risks that could lead to exploitation.
2
How do I fix CVE-2025-21738?
To fix CVE-2025-21738, update the Linux kernel to the latest patched version that addresses this vulnerability.
3
What systems are affected by CVE-2025-21738?
CVE-2025-21738 affects various versions of the Linux kernel that utilize the libata-sff subsystem.
4
What impact does CVE-2025-21738 have on system security?
CVE-2025-21738 could allow an attacker to exploit a vulnerability in buffer management, potentially leading to unauthorized access or system instability.
5
How can I check if my system is vulnerable to CVE-2025-21738?
You can check your Linux kernel version against the fixed versions listed in security advisories or databases to determine if your system is vulnerable to CVE-2025-21738.