# CVE-2025-22104

## Summary

- **CVE ID:** CVE-2025-22104
- **Severity:** HIGH
- **CVSS Score:** 7.1 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
- **CWE:** N/A
- **Published:** Apr 16, 2025
- **Last Modified:** Sep 2, 2026

## Description

In the Linux kernel, the following vulnerability has been resolved:

ibmvnic: Use kernel helpers for hex dumps

Previously, when the driver was printing hex dumps, the buffer was cast
to an 8 byte long and printed using string formatters. If the buffer
size was not a multiple of 8 then a read buffer overflow was possible.

Therefore, create a new ibmvnic function that loops over a buffer and
calls hex_dump_to_buffer instead.

This patch address KASAN reports like the one below:
  ibmvnic 30000003 env3: Login Buffer:
  ibmvnic 30000003 env3: 01000000af000000
  <...>
  ibmvnic 30000003 env3: 2e6d62692e736261
  ibmvnic 30000003 env3: 65050003006d6f63
  ==================================================================
  BUG: KASAN: slab-out-of-bounds in ibmvnic_login+0xacc/0xffc [ibmvnic]
  Read of size 8 at addr c0000001331a9aa8 by task ip/17681
  <...>
  Allocated by task 17681:
  <...>
  ibmvnic_login+0x2f0/0xffc [ibmvnic]
  ibmvnic_open+0x148/0x308 [ibmvnic]
  __dev_open+0x1ac/0x304
  <...>
  The buggy address is located 168 bytes inside of
                allocated 175-byte region [c0000001331a9a00, c0000001331a9aaf)
  <...>
  =================================================================
  ibmvnic 30000003 env3: 000000000033766e

## Affected Products

- Linux — Linux (032c5e82847a2214c3196a90f0aeba0ce252de58)
- Linux — Linux (4.5)
- Linux — Linux (0)
- Linux — Linux (6.14.2)
- Linux — Linux (6.15)
- Linux — Linux (6.1.187)
- Linux — Linux (6.6.156)
- Linux — Linux (6.12.108)

## References

- [CNA](https://git.kernel.org/stable/c/ae6b1d6c1acee3a2000394d83ec9f1028321e207)
- [CNA](https://git.kernel.org/stable/c/d93a6caab5d7d9b5ce034d75b1e1e993338e3852)
- [CNA](https://git.kernel.org/stable/c/19efa170e01207c8ada726f3f6c65b31fcba2a73)
- [CNA](https://git.kernel.org/stable/c/9bc078818ec76344c2e06b81d7aee2df3adecfbf)
- [CNA](https://git.kernel.org/stable/c/005fee039dd845122d313ac8f2122b0d09dc5d7b)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.23%
- **EPSS Percentile:** 13.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._