CVE-2025-21787: team: better TEAM_OPTION_TYPE_STRING validation

Published Feb 27, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

team: better TEAMOPTIONTYPESTRING validation

syzbot reported following splat [1]

Make sure user-provided data contains one nul byte.

[1] BUG: KMSAN: uninit-value in stringnocheck lib/vsprintf.c:633 [inline] BUG: KMSAN: uninit-value in string+0x3ec/0x5f0 lib/vsprintf.c:714 stringnocheck lib/vsprintf.c:633 [inline] string+0x3ec/0x5f0 lib/vsprintf.c:714 vsnprintf+0xa5d/0x1960 lib/vsprintf.c:2843 requestmodule+0x252/0x9f0 kernel/module/kmod.c:149 teammodeget drivers/net/team/teamcore.c:480 [inline] teamchangemode drivers/net/team/teamcore.c:607 [inline] teammodeoptionset+0x437/0x970 drivers/net/team/teamcore.c:1401 teamoptionset drivers/net/team/teamcore.c:375 [inline] teamnloptionssetdoit+0x1339/0x1f90 drivers/net/team/teamcore.c:2662 genlfamilyrcvmsgdoit net/netlink/genetlink.c:1115 [inline] genlfamilyrcvmsg net/netlink/genetlink.c:1195 [inline] genlrcvmsg+0x1214/0x12c0 net/netlink/genetlink.c:1210 netlinkrcvskb+0x375/0x650 net/netlink/afnetlink.c:2543 genlrcv+0x40/0x60 net/netlink/genetlink.c:1219 netlinkunicastkernel net/netlink/afnetlink.c:1322 [inline] netlinkunicast+0xf52/0x1260 net/netlink/afnetlink.c:1348 netlinksendmsg+0x10da/0x11e0 net/netlink/afnetlink.c:1892 socksendmsgnosec net/socket.c:718 [inline] socksendmsg+0x30f/0x380 net/socket.c:733 syssendmsg+0x877/0xb60 net/socket.c:2573 syssendmsg+0x28d/0x3c0 net/socket.c:2627 syssendmsg net/socket.c:2659 [inline] dosyssendmsg net/socket.c:2664 [inline] sesyssendmsg net/socket.c:2662 [inline] x64syssendmsg+0x212/0x3c0 net/socket.c:2662 x64syscall+0x2ed6/0x3c30 arch/x86/include/generated/asm/syscalls64.h:47 dosyscallx64 arch/x86/entry/common.c:52 [inline] dosyscall64+0xcd/0x1e0 arch/x86/entry/common.c:83 entrySYSCALL64afterhwframe+0x77/0x7f

Affected Software

16 affected componentsFixes available
Linux Linux kernel
Microsoft cbl2 kernel 5.15.182.1-1
Microsoft azl3 kernel 6.6.79.1-1
Microsoft cbl2 kernel 5.15.182.1-1
Microsoft cbl2 kernel 5.15.179.1-1
Microsoft azl3 kernel 6.6.78.1-3
Linux Linux kernel>=3.3<6.1.129
Linux Linux kernel>=6.2<6.6.79
Linux Linux kernel>=6.7<6.12.16
Linux Linux kernel>=6.13<6.13.4
Linux Linux kernel=6.14-rc1
Linux Linux kernel=6.14-rc2
IBM Verify Identity Access<=11.0 - 11.0.2
IBM Security Verify Access<=10.0 - 10.0.9.1
IBM Verify Identity Access Container<=11.0 - 11.0.2
IBM Security Verify Access Container<=10.0 - 10.0.9.1

Event History

Feb 27, 2025
CVE Published
via MITRE·02:18 AM
Data Sourced
via MITRE·02:18 AM
Description
Data Sourced
via Red Hat·03:05 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·03:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Apr 9, 2025
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
Updated
via Microsoft·07:00 AM
DescriptionSeverity
Jul 8, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-21787?

The severity of CVE-2025-21787 has been classified as medium due to the potential for uninitialized value exploitation in the Linux kernel.

2

How do I fix CVE-2025-21787?

To fix CVE-2025-21787, you should update to the latest version of the Linux kernel that addresses this vulnerability.

3

What systems are affected by CVE-2025-21787?

CVE-2025-21787 affects all versions of the Linux kernel prior to the patch addressing the vulnerability.

4

Can CVE-2025-21787 lead to remote code execution?

CVE-2025-21787 does not directly lead to remote code execution but can lead to other risks due to uninitialized values.

5

Is user input validation important in CVE-2025-21787?

Yes, proper user input validation is crucial in CVE-2025-21787 to prevent issues with the TEAM_OPTION_TYPE_STRING.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203