---
id: CVE-2025-21789
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  LoongArch: csum: Fix OoB access in IP checksum code for negative lengths

  Commit 69e3a6aa6be2 ("LoongArch: Add checksum optimization for 64-bit
  system") would cause an …
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  LoongArch: csum: Fix OoB access in IP checksum code for negative lengths

  Commit 69e3a6aa6be2 ("LoongArch: Add checksum optimization for 64-bit
  system") would cause an …
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H'
cwe:
  - CWE-125
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 6.4, < 6.6.79'
  - 'linux_kernel >= 6.7, < 6.12.16'
  - 'linux_kernel >= 6.13, < 6.13.4'
  - linux_kernel = 6.14
patched:
  - linux_kernel 6.13.4
published: '2025-02-27'
updated: '2026-07-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-21789'
references:
  - url: 'https://git.kernel.org/stable/c/6287f1a8c16138c2ec750953e35039634018c84a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/964a8895704a22efc06a2a3276b624a5ae985a06'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9f15a8df542c0f08732a67d1a14ee7c22948fb97'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d6508ffff32b44b6d0de06704034e4eef1c307a7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-21789.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-21789'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2348534'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-21789'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-21789'
  - url: >-
      https://lore.kernel.org/linux-cve-announce/2025022609-CVE-2025-21789-9691@gregkh/T
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.0023
epssPercentile: 0.14089
ingestedAt: '2026-07-30T06:53:09.979Z'
scores:
  nvd: 7.3
  vendor: 7.1
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

LoongArch: csum: Fix OoB access in IP checksum code for negative lengths

Commit 69e3a6aa6be2 ("LoongArch: Add checksum optimization for 64-bit
system") would cause an undefined shift and an out-of-bounds read.

Commit 8bd795fedb84 ("arm64: csum: Fix OoB access in IP checksum code
for negative lengths") fixes the same issue on ARM64.

## Affected

- `linux_kernel >= 6.4, < 6.6.79`
- `linux_kernel >= 6.7, < 6.12.16`
- `linux_kernel >= 6.13, < 6.13.4`
- `linux_kernel = 6.14`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.13.4`

## Vendor advisories

- **Red Hat VEX** · Important · updated 2026-09-13 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-21789.json)
