{"id":"DEBIAN-CVE-2025-21867","details":"In the Linux kernel, the following vulnerability has been resolved:  bpf, test_run: Fix use-after-free issue in eth_skb_pkt_type()  KMSAN reported a use-after-free issue in eth_skb_pkt_type()[1]. The cause of the issue was that eth_skb_pkt_type() accessed skb's data that didn't contain an Ethernet header. This occurs when bpf_prog_test_run_xdp() passes an invalid value as the user_data argument to bpf_test_init().  Fix this by returning an error when user_data is less than ETH_HLEN in bpf_test_init(). Additionally, remove the check for \"if (user_size \u003e size)\" as it is unnecessary.  [1] BUG: KMSAN: use-after-free in eth_skb_pkt_type include/linux/etherdevice.h:627 [inline] BUG: KMSAN: use-after-free in eth_type_trans+0x4ee/0x980 net/ethernet/eth.c:165  eth_skb_pkt_type include/linux/etherdevice.h:627 [inline]  eth_type_trans+0x4ee/0x980 net/ethernet/eth.c:165  __xdp_build_skb_from_frame+0x5a8/0xa50 net/core/xdp.c:635  xdp_recv_frames net/bpf/test_run.c:272 [inline]  xdp_test_run_batch net/bpf/test_run.c:361 [inline]  bpf_test_run_xdp_live+0x2954/0x3330 net/bpf/test_run.c:390  bpf_prog_test_run_xdp+0x148e/0x1b10 net/bpf/test_run.c:1318  bpf_prog_test_run+0x5b7/0xa30 kernel/bpf/syscall.c:4371  __sys_bpf+0x6a6/0xe20 kernel/bpf/syscall.c:5777  __do_sys_bpf kernel/bpf/syscall.c:5866 [inline]  __se_sys_bpf kernel/bpf/syscall.c:5864 [inline]  __x64_sys_bpf+0xa4/0xf0 kernel/bpf/syscall.c:5864  x64_sys_call+0x2ea0/0x3d90 arch/x86/include/generated/asm/syscalls_64.h:322  do_syscall_x64 arch/x86/entry/common.c:52 [inline]  do_syscall_64+0xd9/0x1d0 arch/x86/entry/common.c:83  entry_SYSCALL_64_after_hwframe+0x77/0x7f  Uninit was created at:  free_pages_prepare mm/page_alloc.c:1056 [inline]  free_unref_page+0x156/0x1320 mm/page_alloc.c:2657  __free_pages+0xa3/0x1b0 mm/page_alloc.c:4838  bpf_ringbuf_free kernel/bpf/ringbuf.c:226 [inline]  ringbuf_map_free+0xff/0x1e0 kernel/bpf/ringbuf.c:235  bpf_map_free kernel/bpf/syscall.c:838 [inline]  bpf_map_free_deferred+0x17c/0x310 kernel/bpf/syscall.c:862  process_one_work kernel/workqueue.c:3229 [inline]  process_scheduled_works+0xa2b/0x1b60 kernel/workqueue.c:3310  worker_thread+0xedf/0x1550 kernel/workqueue.c:3391  kthread+0x535/0x6b0 kernel/kthread.c:389  ret_from_fork+0x6e/0x90 arch/x86/kernel/process.c:147  ret_from_fork_asm+0x1a/0x30 arch/x86/entry/entry_64.S:244  CPU: 1 UID: 0 PID: 17276 Comm: syz.1.16450 Not tainted 6.12.0-05490-g9bb88c659673 #8 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.3-3.fc41 04/01/2014","modified":"2026-09-01T16:06:10.229929674Z","published":"2025-03-27T14:15:47.750Z","upstream":["CVE-2025-21867"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-21867"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.133-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21867.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.17-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21867.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.17-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-21867.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}