CVE-2025-1722
published 2026-01-20CVE-2025-1722: IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.33%
25.5th percentile
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | concert | >= 1.0.0 < 2.2.0 | 2.2.0 |
| ibm | concert | 1.0.0 – 2.1.0 | — |
| linux | linux_kernel | >= 0 < 6.12.60 | 6.12.60 |
| linux | linux_kernel | >= 6.13.0 < 6.17.10 | 6.17.10 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3qh2-c3gj-pjr3: IBM Concert 1
ghsa_unreviewed·2026-01-20
CVE-2025-1722 [MEDIUM] CWE-244 GHSA-3qh2-c3gj-pjr3: IBM Concert 1
IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information from allocated memory due to improper clearing of heap memory.
OSV
idpf: fix possible vport_config NULL pointer deref in remove
osv·2025-12-16
CVE-2025-68213 idpf: fix possible vport_config NULL pointer deref in remove
idpf: fix possible vport_config NULL pointer deref in remove
In the Linux kernel, the following vulnerability has been resolved:
idpf: fix possible vport_config NULL pointer deref in remove
Attempting to remove the driver will cause a crash in cases where
the vport failed to initialize. Following trace is from an instance where
the driver failed during an attempt to create a VF:
[ 1661.543624] idpf 0000:84:00.7: Device HW Reset initiated
[ 1722.923726] idpf 0000:84:00.7: Transaction timed-out (op:1 cookie:2900 vc_op:1 salt:29 timeout:60000ms)
[ 1723.353263] BUG: kernel NULL pointer dereference, address: 0000000000000028
...
[ 1723.358472] RIP: 0010:idpf_remove+0x11c/0x200 [idpf]
...
[ 1723.364973] Call Trace:
[ 1723.365475]
[ 1723.365972] pci_device_remove+0x42/0xb0
[ 1723.366481] devic
Red Hat
kernel: idpf: fix possible vport_config NULL pointer deref in remove
vendor_redhat·2025-12-16·CVSS 5.5
CVE-2025-68213 [MEDIUM] CWE-476 kernel: idpf: fix possible vport_config NULL pointer deref in remove
kernel: idpf: fix possible vport_config NULL pointer deref in remove
In the Linux kernel, the following vulnerability has been resolved:
idpf: fix possible vport_config NULL pointer deref in remove
Attempting to remove the driver will cause a crash in cases where
the vport failed to initialize. Following trace is from an instance where
the driver failed during an attempt to create a VF:
[ 1661.543624] idpf 0000:84:00.7: Device HW Reset initiated
[ 1722.923726] idpf 0000:84:00.7: Transaction timed-out (op:1 cookie:2900 vc_op:1 salt:29 timeout:60000ms)
[ 1723.353263] BUG: kernel NULL pointer dereference, address: 0000000000000028
...
[ 1723.358472] RIP: 0010:idpf_remove+0x11c/0x200 [idpf]
...
[ 1723.364973] Call Trace:
[ 1723.365475]
[ 1723.365972] pci_device_remove+0x42/0xb0
[ 1723.366481]
No detection rules found.
No public exploits indexed.
2026-01-20
Published