cbcvebase.
CVE-2025-22026
published 2025-04-16

CVE-2025-22026: In the Linux kernel, the following vulnerability has been resolved: nfsd: don't ignore the return code of svc_proc_register() Currently, nfsd_proc_stat_init()…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.1th percentile
In the Linux kernel, the following vulnerability has been resolved: nfsd: don't ignore the return code of svc_proc_register() Currently, nfsd_proc_stat_init() ignores the return value of svc_proc_register(). If the procfile creation fails, then the kernel will WARN when it tries to remove the entry later. Fix nfsd_proc_stat_init() to return the same type of pointer as svc_proc_register(), and fix up nfsd_net_init() to check that and fail the nfsd_net construction if it occurs. svc_proc_register() can fail if the dentry can't be allocated, or if an identical dentry already exists. The second case is pretty unlikely in the nfsd_net construction codepath, so if this happens, return -ENOMEM.

Affected

45 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 10ece754df9a799131a1cf3197e9d26c04ddec22 < 51da899c209a9624e48be416bd30e7ed5cd6c3d851da899c209a9624e48be416bd30e7ed5cd6c3d8
linuxlinux>= 5.10.226 < 5.10.2595.10.259
linuxlinux>= 5.15.166 < 5.15.2105.15.210
linuxlinux>= 5545496966631cd40ad3aa6450be56d0e5773d10 < 51107e768de6821b68aa34a136d07bc7a09cf6c351107e768de6821b68aa34a136d07bc7a09cf6c3
linuxlinux>= 6.1.106 < 6.1.1646.1.164
linuxlinux>= 6.6.47 < 6.6.1256.6.125
linuxlinux>= 6.8.10 < 6.96.9
linuxlinux>= 6f8d6ed3426a17f77628cebfb6a6e2c6f2b2496c < 30405b23b4d5e2a596fb756d48119d7293194e7530405b23b4d5e2a596fb756d48119d7293194e75
linuxlinux>= 73c43bccf25cec9cdec62fc22a513c28a4b28390 < e4316bd85e42b01125b2aab691769234a388b8a3e4316bd85e42b01125b2aab691769234a388b8a3
linuxlinux>= 93483ac5fec62cc1de166051b219d953bb5e4ef4 < 6a59b70fe71ec66c0dd19e2c279c71846a3fb2f06a59b70fe71ec66c0dd19e2c279c71846a3fb2f0
linuxlinux>= 93483ac5fec62cc1de166051b219d953bb5e4ef4 < e31957a819e60cf0bc9a49408765e6095fd3d046e31957a819e60cf0bc9a49408765e6095fd3d046
linuxlinux>= 93483ac5fec62cc1de166051b219d953bb5e4ef4 < 9d9456185fd5f1891c74354ee297f19538141ead9d9456185fd5f1891c74354ee297f19538141ead
linuxlinux>= 93483ac5fec62cc1de166051b219d953bb5e4ef4 < 930b64ca0c511521f0abdd1d57ce52b2a6e3476b930b64ca0c511521f0abdd1d57ce52b2a6e3476b
linuxlinux_kernel< 6.12.246.12.24
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.13 < 6.13.126.13.12
linuxlinux_kernel>= 6.14 < 6.14.26.14.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.