CVE-2025-21993 | Linux Kernel up to 6.1.131/6.6.83/6.12.19/6.13.7 iSCSI boot subnet-mask ibft_attr_show_nic out-of-bounds (Nessus ID 234309 / WID-SEC-2025-0698)
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.1.131/6.6.83/6.12.19/6.13.7. This affects the function ibft_attr_show_nic of the file /sys/firmware/ibft/ethernetX/subnet-mask of the component iSCSI boot. Performing a manipulation results in out-of-bounds read.
This vulnerability was named CVE-2025-21993. The attack needs to be approached within the local network. There is no available exploit.
It is advisable to upgrade the affected component.