---
id: CVE-2025-22104
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ibmvnic: Use kernel helpers for hex dumps

  Previously, when the driver was printing hex dumps, the buffer was cast
  to an 8 byte long and printed using string formatters…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ibmvnic: Use kernel helpers for hex dumps

  Previously, when the driver was printing hex dumps, the buffer was cast
  to an 8 byte long and printed using string formatters…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'
cwe:
  - CWE-125
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 4.5, < 6.14.2'
patched:
  - linux_kernel 6.14.2
published: '2025-04-16'
updated: '2026-09-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-22104'
references:
  - url: 'https://git.kernel.org/stable/c/005fee039dd845122d313ac8f2122b0d09dc5d7b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/19efa170e01207c8ada726f3f6c65b31fcba2a73'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9bc078818ec76344c2e06b81d7aee2df3adecfbf'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ae6b1d6c1acee3a2000394d83ec9f1028321e207'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d93a6caab5d7d9b5ce034d75b1e1e993338e3852'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00227
epssPercentile: 0.11933
ingestedAt: '2026-09-02T13:44:40.881Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ibmvnic: Use kernel helpers for hex dumps

Previously, when the driver was printing hex dumps, the buffer was cast
to an 8 byte long and printed using string formatters. If the buffer
size was not a multiple of 8 then a read buffer overflow was possible.

Therefore, create a new ibmvnic function that loops over a buffer and
calls hex_dump_to_buffer instead.

This patch address KASAN reports like the one below:
  ibmvnic 30000003 env3: Login Buffer:
  ibmvnic 30000003 env3: 01000000af000000
  <...>
  ibmvnic 30000003 env3: 2e6d62692e736261
  ibmvnic 30000003 env3: 65050003006d6f63
  ==================================================================
  BUG: KASAN: slab-out-of-bounds in ibmvnic_login+0xacc/0xffc [ibmvnic]
  Read of size 8 at addr c0000001331a9aa8 by task ip/17681
  <...>
  Allocated by task 17681:
  <...>
  ibmvnic_login+0x2f0/0xffc [ibmvnic]
  ibmvnic_open+0x148/0x308 [ibmvnic]
  __dev_open+0x1ac/0x304
  <...>
  The buggy address is located 168 bytes inside of
                allocated 175-byte region [c0000001331a9a00, c0000001331a9aaf)
  <...>
  =================================================================
  ibmvnic 30000003 env3: 000000000033766e

## Affected

- `linux_kernel >= 4.5, < 6.14.2`

## Remediation

Upgrade past the affected range:

- `linux_kernel 6.14.2`
