cbcvebase.
CVE-2025-22019
published 2025-04-16

CVE-2025-22019: In the Linux kernel, the following vulnerability has been resolved: bcachefs: bch2_ioctl_subvolume_destroy() fixes bch2_evict_subvolume_inodes() was getting…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
8.0th percentile
In the Linux kernel, the following vulnerability has been resolved: bcachefs: bch2_ioctl_subvolume_destroy() fixes bch2_evict_subvolume_inodes() was getting stuck - due to incorrectly pruning the dcache. Also, fix missing permissions checks.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.22-1 (forky)linux 6.12.22-1 (forky)
linuxlinux
linuxlinux>= 1c6fdbd8f2465ddfb73a01ec620cbf3d14044e1a < 9e6e83e1e2d01b99e70cd7812d7f758a8def9fc89e6e83e1e2d01b99e70cd7812d7f758a8def9fc8
linuxlinux>= 1c6fdbd8f2465ddfb73a01ec620cbf3d14044e1a < 82383abd39abd635511b8956284a5cc8134c4dc182383abd39abd635511b8956284a5cc8134c4dc1
linuxlinux>= 1c6fdbd8f2465ddfb73a01ec620cbf3d14044e1a < 558317a5c61045d460a37372181e7b43c0c002bb558317a5c61045d460a37372181e7b43c0c002bb
linuxlinux>= 1c6fdbd8f2465ddfb73a01ec620cbf3d14044e1a < 707549600c4a012ed71c0204a7992a679880bf33707549600c4a012ed71c0204a7992a679880bf33
linuxlinux_kernel>= 0 < 6.12.22-16.12.22-1
linuxlinux_kernel>= 0 < 6.12.22-16.12.22-1
linuxlinux_kernel>= 0 < 6.8.0-86.876.8.0-86.87
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.13 < 6.13.106.13.10
linuxlinux_kernel>= 6.14 < 6.14.26.14.2
linuxlinux_kernel>= 6.7 < 6.12.226.12.22

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.