CVE-2025-2073

Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an out-of-bounds read, potentially leading to information disclosure
CVSS

No CVSS.

References
Link Resource
https://issues.chromium.org/issues/b/380043638 Broken Link
https://issuetracker.google.com/issues/380043638 Exploit Issue Tracking Mailing List
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:google:chrome_os:16093.103.0:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:4.19:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.10:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:6.1:-:*:*:*:*:*:*

History

11 Jul 2025, 14:04

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:6.1:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:4.19:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.15:-:*:*:*:*:*:*
cpe:2.3:o:google:chrome_os:16093.103.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:5.10:-:*:*:*:*:*:*
References () https://issuetracker.google.com/issues/380043638 - () https://issuetracker.google.com/issues/380043638 - Exploit, Issue Tracking, Mailing List
References () https://issues.chromium.org/issues/b/380043638 - () https://issues.chromium.org/issues/b/380043638 - Broken Link
First Time Google chrome Os
Google
Linux linux Kernel
Linux

06 May 2025, 01:15

Type Values Removed Values Added
Summary Out-of-Bounds Read in ip_set_bitmap_ip.c in Google ChromeOS Kernel Versions 6.1, 5.15, 5.10, 5.4, 4.19. on All devices where Termina is used allows an attacker with CAP_NET_ADMIN privileges to cause memory corruption and potentially escalate privileges via crafted ipset commands. Out-of-Bounds Read in netfilter/ipset in Linux Kernel ChromeOS [6.1, 5.15, 5.10, 5.4, 4.19] allows a local attacker with low privileges to trigger an out-of-bounds read, potentially leading to information disclosure

16 Apr 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-16 23:15

Updated : 2025-07-11 14:04


NVD link : CVE-2025-2073

Mitre link : CVE-2025-2073


JSON object : View

Products Affected

linux

  • linux_kernel

google

  • chrome_os
CWE

No CWE.