{"id":"CVE-2025-21789","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: csum: Fix OoB access in IP checksum code for negative lengths\n\nCommit 69e3a6aa6be2 (\"LoongArch: Add checksum optimization for 64-bit\nsystem\") would cause an …","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: csum: Fix OoB access in IP checksum code for negative lengths\n\nCommit 69e3a6aa6be2 (\"LoongArch: Add checksum optimization for 64-bit\nsystem\") would cause an …","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H","cwe":["CWE-125"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 6.4, < 6.6.79","linux_kernel >= 6.7, < 6.12.16","linux_kernel >= 6.13, < 6.13.4","linux_kernel = 6.14"],"patched":["linux_kernel 6.13.4"],"published":"2025-02-27","updated":"2026-07-30","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-21789","references":[{"url":"https://git.kernel.org/stable/c/6287f1a8c16138c2ec750953e35039634018c84a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/964a8895704a22efc06a2a3276b624a5ae985a06","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9f15a8df542c0f08732a67d1a14ee7c22948fb97","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d6508ffff32b44b6d0de06704034e4eef1c307a7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-21789.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-21789"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2348534"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-21789"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-21789"},{"url":"https://lore.kernel.org/linux-cve-announce/2025022609-CVE-2025-21789-9691@gregkh/T"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00226,"epssPercentile":0.13491,"ingestedAt":"2026-07-30T06:53:09.979Z","scores":{"nvd":7.3,"vendor":7.1},"slug":"CVE-2025-21789","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nLoongArch: csum: Fix OoB access in IP checksum code for negative lengths\n\nCommit 69e3a6aa6be2 (\"LoongArch: Add checksum optimization for 64-bit\nsystem\") would cause an undefined shift and an out-of-bounds read.\n\nCommit 8bd795fedb84 (\"arm64: csum: Fix OoB access in IP checksum code\nfor negative lengths\") fixes the same issue on ARM64.\n\n## Affected\n\n- `linux_kernel >= 6.4, < 6.6.79`\n- `linux_kernel >= 6.7, < 6.12.16`\n- `linux_kernel >= 6.13, < 6.13.4`\n- `linux_kernel = 6.14`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 6.13.4`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · updated 2026-09-13 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-21789.json)","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":40.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}