cbcvebase.
CVE-2025-22011
published 2025-04-08

CVE-2025-22011: In the Linux kernel, the following vulnerability has been resolved: ARM: dts: bcm2711: Fix xHCI power-domain During s2idle tests on the Raspberry CM4 the VPU…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.9th percentile
In the Linux kernel, the following vulnerability has been resolved: ARM: dts: bcm2711: Fix xHCI power-domain During s2idle tests on the Raspberry CM4 the VPU firmware always crashes on xHCI power-domain resume: root@raspberrypi:/sys/power# echo freeze > state [ 70.724347] xhci_suspend finished [ 70.727730] xhci_plat_suspend finished [ 70.755624] bcm2835-power bcm2835-power: Power grafx off [ 70.761127] USB: Set power to 0 [ 74.653040] USB: Failed to set power to 1 (-110) This seems to be caused because of the mixed usage of raspberrypi-power and bcm2835-power at the same time. So avoid the usage of the VPU firmware power-domain driver, which prevents the VPU crash.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.21-1 (forky)linux 6.12.21-1 (forky)
linuxlinux
linuxlinux>= 522c35e08b53f157ad3e51848caa861b258001e4 < b8a47aa0b3df701d0fc41b3caf78d00571776be0b8a47aa0b3df701d0fc41b3caf78d00571776be0
linuxlinux>= 522c35e08b53f157ad3e51848caa861b258001e4 < 393947e06867923d4c2be380d46efd03407a8ce2393947e06867923d4c2be380d46efd03407a8ce2
linuxlinux>= 522c35e08b53f157ad3e51848caa861b258001e4 < f44fa354a0715577ca32b085f6f60bcf32c748ddf44fa354a0715577ca32b085f6f60bcf32c748dd
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.21-16.12.21-1
linuxlinux_kernel>= 0 < 6.12.21-16.12.21-1
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 6.13 < 6.13.96.13.9
linuxlinux_kernel>= 6.8 < 6.12.216.12.21

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.