cbcvebase.
CVE-2025-22017
published 2025-04-08

CVE-2025-22017: In the Linux kernel, the following vulnerability has been resolved: devlink: fix xa_alloc_cyclic() error handling In case of returning 1 from xa_alloc_cyclic()…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
8.2th percentile
In the Linux kernel, the following vulnerability has been resolved: devlink: fix xa_alloc_cyclic() error handling In case of returning 1 from xa_alloc_cyclic() (wrapping) ERR_PTR(1) will be returned, which will cause IS_ERR() to be false. Which can lead to dereference not allocated pointer (rel). Fix it by checking if err is lower than zero. This wasn't found in real usecase, only noticed. Credit to Pierre.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.21-1 (forky)linux 6.12.21-1 (forky)
linuxlinux
linuxlinux>= c137743bce02b18c1537d4681aa515f7b80bf0a8 < f8aaa38cfaf6f20afa4db36b6529032fb69165dcf8aaa38cfaf6f20afa4db36b6529032fb69165dc
linuxlinux>= c137743bce02b18c1537d4681aa515f7b80bf0a8 < 466132f6d28a7e47a82501fe1c46b8f90487412e466132f6d28a7e47a82501fe1c46b8f90487412e
linuxlinux>= c137743bce02b18c1537d4681aa515f7b80bf0a8 < f3b97b7d4bf316c3991e5634c9f4847c2df35478f3b97b7d4bf316c3991e5634c9f4847c2df35478
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.21-16.12.21-1
linuxlinux_kernel>= 0 < 6.12.21-16.12.21-1
linuxlinux_kernel>= 0 < 6.8.0-84.846.8.0-84.84
linuxlinux_kernel>= 6.13 < 6.13.96.13.9
linuxlinux_kernel>= 6.7 < 6.12.216.12.21

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.9MEDIUM
vendor_ubuntu5.9MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.