CVE-2025-21993 | Linux Kernel up to 6.1.131/6.6.83/6.12.19/6.13.7 iSCSI boot subnet-mask ibft_attr_show_nic out-of-bounds
A vulnerability classified as problematic was found in Linux Kernel up to 6.1.131/6.6.83/6.12.19/6.13.7. This vulnerability affects the function ibft_attr_show_nic of the file /sys/firmware/ibft/ethernetX/subnet-mask of the component iSCSI boot. The manipulation leads to out-of-bounds read.
This vulnerability was named CVE-2025-21993. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.