CVE-2025-22107
In the Linux kernel, the following vulnerability has been resolved:
net: dsa: sja1105: fix kasan out-of-bounds warning in sja1105_table_delete_entry()
There are actually 2 problems: - deleting the last element doesn't require the memmove of elements [i + 1, end) over it. Actually, element i+1 is out of bounds. - The memmove itself should move size - i - 1 elements, because the last element is out of bounds.
The out-of-bounds element still remains out of bounds after being accessed, so the problem is only that we touch it, not that it becomes in active use. But I suppose it can lead to issues if the out-of-bounds element is part of an unmapped page.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1059Command and Scripting Interpreterexecution65 % - Impacto secundario
T1499Endpoint Denial of Serviceimpact55 %
Vulnerabilidad local (AV:L) sin interacción de usuario en kernel Linux que accede a memoria fuera de límites, permitiendo escalada de privilegios o denegación de servicio mediante memmove incorrecto en tablas DSA.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-125
Referencias
- https://git.kernel.org/stable/c/031e00249e9e6bee72ba66701c8f83b45fc4b8a2
- https://git.kernel.org/stable/c/4584486cfcca24b7b586da3377eb3cffd48669ec
- https://git.kernel.org/stable/c/59b97641de03c081f26b3a8876628c765b5faa25
- https://git.kernel.org/stable/c/5f2b28b79d2d1946ee36ad8b3dc0066f73c90481
- https://git.kernel.org/stable/c/b52153da1f42e2f4d6259257a7ba027331671a93
- https://git.kernel.org/stable/c/f117d0467215d7f1d445ae16d2c799637e63dc6c
- https://git.kernel.org/stable/c/f85b9bfb08ba2b642d1810c6c4ae1e7b46f1776a
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-22107",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6666cebc5e306f49a25bd20aa8c1cb8ef8950df5",
"lessThan": "f85b9bfb08ba2b642d1810c6c4ae1e7b46f1776a",
"versionType": "git"
},
{
"status": "affected",
"version": "6666cebc5e306f49a25bd20aa8c1cb8ef8950df5",
"lessThan": "f117d0467215d7f1d445ae16d2c799637e63dc6c",
"versionType": "git"
},
{
"status": "affected",
"version": "6666cebc5e306f49a25bd20aa8c1cb8ef8950df5",
"lessThan": "b52153da1f42e2f4d6259257a7ba027331671a93",
"versionType": "git"
},
{
"status": "affected",
"version": "6666cebc5e306f49a25bd20aa8c1cb8ef8950df5",
"lessThan": "4584486cfcca24b7b586da3377eb3cffd48669ec",
"versionType": "git"
},
{
"status": "affected",
"version": "6666cebc5e306f49a25bd20aa8c1cb8ef8950df5",
"lessThan": "031e00249e9e6bee72ba66701c8f83b45fc4b8a2",
"versionType": "git"
},
{
"status": "affected",
"version": "6666cebc5e306f49a25bd20aa8c1cb8ef8950df5",
"lessThan": "59b97641de03c081f26b3a8876628c765b5faa25",
"versionType": "git"
},
{
"status": "affected",
"version": "6666cebc5e306f49a25bd20aa8c1cb8ef8950df5",
"lessThan": "5f2b28b79d2d1946ee36ad8b3dc0066f73c90481",
"versionType": "git"
}
],
"programFiles": [
"drivers/net/dsa/sja1105/sja1105_static_config.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.2",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.258",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.209",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.160",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.120",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.59",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.14.2",
"versionType": "semver",
"lessThanOrEqual": "6.14.*"
},
{
"status": "unaffected",
"version": "6.15",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/net/dsa/sja1105/sja1105_static_config.c"
],
"defaultStatus": "affected"
}
]
},
{
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"affectedData": [
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"vendor": "Siemens",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"versions": [
{
"status": "affected",
"version": "V3.1.6",
"lessThan": "*",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2025-04-16T15:16:04.997",
"references": [
{
"url": "https://git.kernel.org/stable/c/031e00249e9e6bee72ba66701c8f83b45fc4b8a2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4584486cfcca24b7b586da3377eb3cffd48669ec",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/59b97641de03c081f26b3a8876628c765b5faa25",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5f2b28b79d2d1946ee36ad8b3dc0066f73c90481",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b52153da1f42e2f4d6259257a7ba027331671a93",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f117d0467215d7f1d445ae16d2c799637e63dc6c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f85b9bfb08ba2b642d1810c6c4ae1e7b46f1776a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-019113.html",
"source": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet: dsa: sja1105: fix kasan out-of-bounds warning in sja1105_table_delete_entry()\n\nThere are actually 2 problems:\n- deleting the last element doesn't require the memmove of elements\n [i + 1, end) over it. Actually, element i+1 is out of bounds.\n- The memmove itself should move size - i - 1 elements, because the last\n element is out of bounds.\n\nThe out-of-bounds element still remains out of bounds after being\naccessed, so the problem is only that we touch it, not that it becomes\nin active use. But I suppose it can lead to issues if the out-of-bounds\nelement is part of an unmapped page."
},
{
"lang": "es",
"value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: net: dsa: sja1105: corrección de la advertencia de kasan fuera de los límites en sja1105_table_delete_entry() En realidad, hay 2 problemas: - eliminar el último elemento no requiere el memmove de elementos [i + 1, fin) sobre él. En realidad, el elemento i + 1 está fuera de los límites. - El memmove en sí mismo debería mover tamaño - i - 1 elementos, porque el último elemento está fuera de los límites. El elemento fuera de los límites sigue estando fuera de los límites después de ser accedido, por lo que el problema es solo que lo tocamos, no que se vuelva en uso activo. Pero supongo que puede conducir a problemas si el elemento fuera de los límites es parte de una página no asignada."
}
],
"lastModified": "2026-07-14T13:17:31.170",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B485FDF4-1B47-438C-876C-E449A567F0DF",
"versionEndExcluding": "6.14.2",
"versionStartIncluding": "5.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}