{"id":"DEBIAN-CVE-2025-21653","details":"In the Linux kernel, the following vulnerability has been resolved:  net_sched: cls_flow: validate TCA_FLOW_RSHIFT attribute  syzbot found that TCA_FLOW_RSHIFT attribute was not validated. Right shitfing a 32bit integer is undefined for large shift values.  UBSAN: shift-out-of-bounds in net/sched/cls_flow.c:329:23 shift exponent 9445 is too large for 32-bit type 'u32' (aka 'unsigned int') CPU: 1 UID: 0 PID: 54 Comm: kworker/u8:3 Not tainted 6.13.0-rc3-syzkaller-00180-g4f619d518db9 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 09/13/2024 Workqueue: ipv6_addrconf addrconf_dad_work Call Trace:  \u003cTASK\u003e   __dump_stack lib/dump_stack.c:94 [inline]   dump_stack_lvl+0x241/0x360 lib/dump_stack.c:120   ubsan_epilogue lib/ubsan.c:231 [inline]   __ubsan_handle_shift_out_of_bounds+0x3c8/0x420 lib/ubsan.c:468   flow_classify+0x24d5/0x25b0 net/sched/cls_flow.c:329   tc_classify include/net/tc_wrapper.h:197 [inline]   __tcf_classify net/sched/cls_api.c:1771 [inline]   tcf_classify+0x420/0x1160 net/sched/cls_api.c:1867   sfb_classify net/sched/sch_sfb.c:260 [inline]   sfb_enqueue+0x3ad/0x18b0 net/sched/sch_sfb.c:318   dev_qdisc_enqueue+0x4b/0x290 net/core/dev.c:3793   __dev_xmit_skb net/core/dev.c:3889 [inline]   __dev_queue_xmit+0xf0e/0x3f50 net/core/dev.c:4400   dev_queue_xmit include/linux/netdevice.h:3168 [inline]   neigh_hh_output include/net/neighbour.h:523 [inline]   neigh_output include/net/neighbour.h:537 [inline]   ip_finish_output2+0xd41/0x1390 net/ipv4/ip_output.c:236   iptunnel_xmit+0x55d/0x9b0 net/ipv4/ip_tunnel_core.c:82   udp_tunnel_xmit_skb+0x262/0x3b0 net/ipv4/udp_tunnel_core.c:173   geneve_xmit_skb drivers/net/geneve.c:916 [inline]   geneve_xmit+0x21dc/0x2d00 drivers/net/geneve.c:1039   __netdev_start_xmit include/linux/netdevice.h:5002 [inline]   netdev_start_xmit include/linux/netdevice.h:5011 [inline]   xmit_one net/core/dev.c:3590 [inline]   dev_hard_start_xmit+0x27a/0x7d0 net/core/dev.c:3606   __dev_queue_xmit+0x1b73/0x3f50 net/core/dev.c:4434","modified":"2026-09-01T16:06:09.544064546Z","published":"2025-01-19T11:15:10.940Z","upstream":["CVE-2025-21653"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-21653"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.128-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21653.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21653.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.10-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21653.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}