cbcvebase.
CVE-2025-22016
published 2025-04-08

CVE-2025-22016: In the Linux kernel, the following vulnerability has been resolved: dpll: fix xa_alloc_cyclic() error handling In case of returning 1 from xa_alloc_cyclic()…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.9th percentile
In the Linux kernel, the following vulnerability has been resolved: dpll: fix xa_alloc_cyclic() error handling In case of returning 1 from xa_alloc_cyclic() (wrapping) ERR_PTR(1) will be returned, which will cause IS_ERR() to be false. Which can lead to dereference not allocated pointer (pin). Fix it by checking if err is lower than zero. This wasn't found in real usecase, only noticed. Credit to Pierre.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.21-1 (forky)linux 6.12.21-1 (forky)
linuxlinux
linuxlinux>= 97f265ef7f5b526b33d6030b2a1fc69a2259bf4a < cb2f8a5c1fd9e7a1fefa23afe20570e16da1ada4cb2f8a5c1fd9e7a1fefa23afe20570e16da1ada4
linuxlinux>= 97f265ef7f5b526b33d6030b2a1fc69a2259bf4a < 4d350043be684762e581d9bdd32d543621d01a9c4d350043be684762e581d9bdd32d543621d01a9c
linuxlinux>= 97f265ef7f5b526b33d6030b2a1fc69a2259bf4a < 3614bf90130d60f191a5fe218d04f6251c678e133614bf90130d60f191a5fe218d04f6251c678e13
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.21-16.12.21-1
linuxlinux_kernel>= 0 < 6.12.21-16.12.21-1
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 6.13 < 6.13.96.13.9
linuxlinux_kernel>= 6.8 < 6.12.216.12.21

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.