cbcvebase.
CVE-2025-22049
published 2025-04-16

CVE-2025-22049: In the Linux kernel, the following vulnerability has been resolved: LoongArch: Increase ARCH_DMA_MINALIGN up to 16 ARCH_DMA_MINALIGN is 1 by default, but some…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
10.0th percentile
In the Linux kernel, the following vulnerability has been resolved: LoongArch: Increase ARCH_DMA_MINALIGN up to 16 ARCH_DMA_MINALIGN is 1 by default, but some LoongArch-specific devices (such as APBDMA) require 16 bytes alignment. When the data buffer length is too small, the hardware may make an error writing cacheline. Thus, it is dangerous to allocate a small memory buffer for DMA. It's always safe to define ARCH_DMA_MINALIGN as L1_CACHE_BYTES but unnecessary (kmalloc() need small memory objects). Therefore, just increase it to 16.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= fa96b57c149061f71a70bd6582d995f6424fbbf4 < f39af67f03b564b763b06e44cb960c10a382d54af39af67f03b564b763b06e44cb960c10a382d54a
linuxlinux>= fa96b57c149061f71a70bd6582d995f6424fbbf4 < 279ec25c2df49fba1cd9488f2ddd045d9cb2112e279ec25c2df49fba1cd9488f2ddd045d9cb2112e
linuxlinux>= fa96b57c149061f71a70bd6582d995f6424fbbf4 < 1d0def2d1658666ec1f32c9495df60e7411e3c821d0def2d1658666ec1f32c9495df60e7411e3c82
linuxlinux>= fa96b57c149061f71a70bd6582d995f6424fbbf4 < bfff341cac7c650e6ca8d10503725992f5564d0fbfff341cac7c650e6ca8d10503725992f5564d0f
linuxlinux>= fa96b57c149061f71a70bd6582d995f6424fbbf4 < 8b82aea3666f8f2c78f86148d78aea99c46e0f828b82aea3666f8f2c78f86148d78aea99c46e0f82
linuxlinux>= fa96b57c149061f71a70bd6582d995f6424fbbf4 < 4103cfe9dcb88010ae4911d3ff417457d1b6a7204103cfe9dcb88010ae4911d3ff417457d1b6a720
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 5.19 < 6.1.1346.1.134
linuxlinux_kernel>= 6.13 < 6.13.116.13.11
linuxlinux_kernel>= 6.14 < 6.14.26.14.2
linuxlinux_kernel>= 6.2 < 6.6.876.6.87
linuxlinux_kernel>= 6.7 < 6.12.236.12.23
msrcazl3_kernel_6.6.85.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.