cbcvebase.
CVE-2025-22022
published 2025-04-16

CVE-2025-22022: In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Apply the link chain quirk on NEC isoc endpoints Two clearly different specimens…

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.19%
8.7th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Apply the link chain quirk on NEC isoc endpoints Two clearly different specimens of NEC uPD720200 (one with start/stop bug, one without) were seen to cause IOMMU faults after some Missed Service Errors. Faulting address is immediately after a transfer ring segment and patched dynamic debug messages revealed that the MSE was received when waiting for a TD near the end of that segment: [ 1.041954] xhci_hcd: Miss service interval error for slot 1 ep 2 expected TD DMA ffa08fe0 [ 1.042120] xhci_hcd: AMD-Vi: Event logged [IO_PAGE_FAULT domain=0x0005 address=0xffa09000 flags=0x0000] [ 1.042146] xhci_hcd: AMD-Vi: Event logged [IO_PAGE_FAULT domain=0x0005 address=0xffa09040 flags=0x0000] It gets even funnier if the next page is a ring segment accessible to the HC. Below, it reports MSE in segment at ff1e8000, plows through a zero-filled page at ff1e9000 and starts reporting events for TRBs in page at ff1ea000 every microframe, instead of jumping to seg ff1e6000. [ 7.041671] xhci_hcd: Miss service interval error for slot 1 ep 2 expected TD DMA ff1e8fe0 [ 7.041999] xhci_hcd: Miss service interval error for slot 1 ep 2 expected TD DMA ff1e8fe0 [ 7.042011] xhci_hcd: WARN: buffer overrun event for slot 1 ep 2 on endpoint [ 7.042028] xhci_hcd: All TDs skipped for slot 1 ep 2. Clear skip flag. [ 7.042134] xhci_hcd: WARN: buffer overrun event for slot 1 ep 2 on endpoint [ 7.042138] xhci_hcd: ERROR Transfer event TRB DMA ptr not part of current TD ep_index 2 comp_code 31 [ 7.042144] xhci_hcd: Looking for event-dma 00000000ff1ea040 trb-start 00000000ff1e6820 trb-end 00000000ff1e6820 [ 7.042259] xhci_hcd: WARN: buffer overrun event for slot 1 ep 2 on endpoint [ 7.042262] xhci_hcd: ERROR Transfer event TRB DMA ptr not part of current TD ep_index 2 comp_code 31 [ 7.042266] xhci_hcd: Looking for event-dma 00000000ff1ea050 trb-start 00000000ff1e6820 trb-end 00000000ff1e6820 At some point completion events

Affected

56 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
debianlinux-6.1< linux 6.1.162-1 (bookworm)linux 6.1.162-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 3.0.9 < 3.13.1
linuxlinux>= 3.1.1 < 3.23.2
linuxlinux>= 7e393a834b41001174a8fb3ae3bc23a749467760 < abf2df229b6a9172cc1827749c1a446d28e00a2eabf2df229b6a9172cc1827749c1a446d28e00a2e
linuxlinux>= 7e393a834b41001174a8fb3ae3bc23a749467760 < 8b586de6f03c850ff48d42e539b4708d1f3f8f1a8b586de6f03c850ff48d42e539b4708d1f3f8f1a
linuxlinux>= 7e393a834b41001174a8fb3ae3bc23a749467760 < 1143f790a6316201dc8f067eba4c94ea97ecb6ca1143f790a6316201dc8f067eba4c94ea97ecb6ca
linuxlinux>= 7e393a834b41001174a8fb3ae3bc23a749467760 < dbf427663ce272070d3004b5fca63a4a537d781cdbf427663ce272070d3004b5fca63a4a537d781c
linuxlinux>= 7e393a834b41001174a8fb3ae3bc23a749467760 < a4931d9fb99eb5462f3eaa231999d279c40afb21a4931d9fb99eb5462f3eaa231999d279c40afb21
linuxlinux>= 7e393a834b41001174a8fb3ae3bc23a749467760 < 43a18225150ce874d23b37761c302a5dffee159543a18225150ce874d23b37761c302a5dffee1595
linuxlinux>= 7e393a834b41001174a8fb3ae3bc23a749467760 < 061a1683bae6ef56ab8fa392725ba7495515cd1d061a1683bae6ef56ab8fa392725ba7495515cd1d
linuxlinux>= 7e393a834b41001174a8fb3ae3bc23a749467760 < bb0ba4cb1065e87f9cc75db1fa454e56d0894d01bb0ba4cb1065e87f9cc75db1fa454e56d0894d01
linuxlinux_kernel< 6.12.226.12.22
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.249-15.10.249-1
linuxlinux_kernel>= 0 < 6.1.162-16.1.162-1
linuxlinux_kernel>= 0 < 6.12.22-16.12.22-1
linuxlinux_kernel>= 0 < 6.12.22-16.12.22-1
linuxlinux_kernel>= 0 < 5.15.0-173.1835.15.0-173.183
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.13 < 6.13.106.13.10
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.