CVE-2025-21743: usbnet: ipheth: fix possible overflow in DPE length check
In the Linux kernel, the following vulnerability has been resolved:
usbnet: ipheth: fix possible overflow in DPE length check
Originally, it was possible for the DPE length check to overflow if
wDatagramIndex + wDatagramLength > U16_MAX. This could lead to an OoB
read.
Move the wDatagramIndex term to the other side of the inequality.
An existing condition ensures that wDatagramIndex < urb->actual_length.
Security readout for executives and security teams
Plain-English summary
CVE-2025-21743 is a Linux kernel flaw in the usbnet ipheth driver. A bad length calculation can overflow and cause the kernel to read outside the expected buffer. Business risk is highest for Linux systems where this driver is present and reachable through local use or attached USB networking paths.
Executive priority
Treat as high priority for Linux endpoint, appliance, and device fleets with USB networking exposure. It is not currently evidenced as exploited here, but kernel out-of-bounds reads can affect confidentiality and availability.
Technical view
The ipheth DPE length check could overflow when wDatagramIndex plus wDatagramLength exceeds U16_MAX, creating an out-of-bounds read condition. The stated fix moves wDatagramIndex to the other side of the inequality. The issue is classified as CWE-125 with CVSS 3.1 score 7.1.
Likely exposure
Exposure is likely limited to Linux systems with affected kernel builds and the usbnet ipheth driver present or usable. The provided version data is not a complete distro matrix, so vendor kernel advisories and backport status must be checked.
Exploitation context
The bundle does not show CISA KEV listing, and no provided source reports active exploitation. CVSS marks the attack vector as local, low complexity, low privilege, no user interaction, with high confidentiality and availability impact.
Researcher notes
The evidence identifies the vulnerable logic and upstream stable commits, but affected-version metadata is sparse and partly ambiguous. Avoid assuming distro exposure from upstream versions alone; confirm with vendor backport records and local kernel configuration.
Mitigation direction
Update to a Linux kernel containing the referenced stable fix commits.
Check distribution advisories for backported fixes before relying on upstream version numbers.
Restrict untrusted local USB/network-device access where operationally feasible.
Track vendor guidance if running appliance, embedded, or custom kernels.
Validation and detection
Inventory Linux kernel versions across servers, endpoints, and appliances.
Check whether the ipheth driver is built, loaded, or available.
Map installed kernels against distro advisories and the cited stable commits.
Confirm patched kernels are running after maintenance reboots.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-125: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-125 · source CWE mapping
Out-of-bounds Read
Out-of-bounds Read represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.