cbcvebase.
CVE-2025-22018
published 2025-04-16

CVE-2025-22018: In the Linux kernel, the following vulnerability has been resolved: atm: Fix NULL pointer dereference When MPOA_cache_impos_rcvd() receives the msg, it can…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.6th percentile
In the Linux kernel, the following vulnerability has been resolved: atm: Fix NULL pointer dereference When MPOA_cache_impos_rcvd() receives the msg, it can trigger Null Pointer Dereference Vulnerability if both entry and holding_time are NULL. Because there is only for the situation where entry is NULL and holding_time exists, it can be passed when both entry and holding_time are NULL. If these are NULL, the entry will be passd to eg_cache_put() as parameter and it is referenced by entry->use code in it. kasan log: [ 3.316691] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000006:I [ 3.317568] KASAN: null-ptr-deref in range [0x0000000000000030-0x0000000000000037] [ 3.318188] CPU: 3 UID: 0 PID: 79 Comm: ex Not tainted 6.14.0-rc2 #102 [ 3.318601] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 [ 3.319298] RIP: 0010:eg_cache_remove_entry+0xa5/0x470 [ 3.319677] Code: c1 f7 6e fd 48 c7 c7 00 7e 38 b2 e8 95 64 54 fd 48 c7 c7 40 7e 38 b2 48 89 ee e80 [ 3.321220] RSP: 0018:ffff88800583f8a8 EFLAGS: 00010006 [ 3.321596] RAX: 0000000000000006 RBX: ffff888005989000 RCX: ffffffffaecc2d8e [ 3.322112] RDX: 0000000000000000 RSI: 0000000000000004 RDI: 0000000000000030 [ 3.322643] RBP: 0000000000000000 R08: 0000000000000000 R09: fffffbfff6558b88 [ 3.323181] R10: 0000000000000003 R11: 203a207972746e65 R12: 1ffff11000b07f15 [ 3.323707] R13: dffffc0000000000 R14: ffff888005989000 R15: ffff888005989068 [ 3.324185] FS: 000000001b6313c0(0000) GS:ffff88806d380000(0000) knlGS:0000000000000000 [ 3.325042] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 3.325545] CR2: 00000000004b4b40 CR3: 000000000248e000 CR4: 00000000000006f0 [ 3.326430] Call Trace: [ 3.326725] [ 3.326927] ? die_addr+0x3c/0xa0 [ 3.327330] ? exc_general_protection+0x161/0x2a0 [ 3.327662] ? asm_exc_general_protection+0x26/0x30 [ 3.328214] ? vprintk_emit+0x15e/0x420 [ 3.328543] ? eg_cache_remove_entry+0xa5/0x470 [ 3.328910] ? eg_cache_remove_entry+0x9a/0x470

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
debianlinux-6.1< linux 6.1.133-1 (bookworm)linux 6.1.133-1 (bookworm)
linuxlinux
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < ab92f51c7f53a08f1a686bfb80690ebb3672357dab92f51c7f53a08f1a686bfb80690ebb3672357d
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 1505f9b720656b17865e4166ab002960162bf6791505f9b720656b17865e4166ab002960162bf679
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < d7f1e4a53a51cc6ba833afcb40439f18dab61c1fd7f1e4a53a51cc6ba833afcb40439f18dab61c1f
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 0ef6e49881b6b50ac454cb9d6501d009fdceb6fc0ef6e49881b6b50ac454cb9d6501d009fdceb6fc
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 9da6b6340dbcf0f60ae3ec6a7d6438337c32518a9da6b6340dbcf0f60ae3ec6a7d6438337c32518a
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 09691f367df44fe93255274d80a439f9bb3263fc09691f367df44fe93255274d80a439f9bb3263fc
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 3c23bb2c894e9ef2727682f98c341b20f78c90133c23bb2c894e9ef2727682f98c341b20f78c9013
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < 14c7aca5ba2740973de27c1bb8df77b4dcb6f77514c7aca5ba2740973de27c1bb8df77b4dcb6f775
linuxlinux>= 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 < bf2986fcf82a449441f9ee4335df19be19e83970bf2986fcf82a449441f9ee4335df19be19e83970
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.133-16.1.133-1
linuxlinux_kernel>= 0 < 6.12.22-16.12.22-1
linuxlinux_kernel>= 0 < 6.12.22-16.12.22-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-86.876.8.0-86.87
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 0 < 5.4.0-218.2385.4.0-218.238
linuxlinux_kernel>= 2.6.12 < 5.4.2925.4.292
linuxlinux_kernel>= 5.11 < 5.15.1805.15.180
linuxlinux_kernel>= 5.16 < 6.1.1336.1.133
linuxlinux_kernel>= 5.5 < 5.10.2365.10.236
linuxlinux_kernel>= 6.13 < 6.13.106.13.10

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.