cbcvebase.
CVE-2025-22050
published 2025-04-16

CVE-2025-22050: In the Linux kernel, the following vulnerability has been resolved: usbnet:fix NPE during rx_complete Missing usbnet_going_away Check in Critical Path. The…

PriorityP418medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.18%
7.7th percentile
In the Linux kernel, the following vulnerability has been resolved: usbnet:fix NPE during rx_complete Missing usbnet_going_away Check in Critical Path. The usb_submit_urb function lacks a usbnet_going_away validation, whereas __usbnet_queue_skb includes this check. This inconsistency creates a race condition where: A URB request may succeed, but the corresponding SKB data fails to be queued. Subsequent processes: (e.g., rx_complete → defer_bh → __skb_unlink(skb, list)) attempt to access skb->next, triggering a NULL pointer dereference (Kernel Panic).

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 04e906839a053f092ef53f4fb2d610983412b904 < d689645cd1594ea1d13cb0c404f8ad1011353e0ed689645cd1594ea1d13cb0c404f8ad1011353e0e
linuxlinux>= 04e906839a053f092ef53f4fb2d610983412b904 < 0c30988588b28393e3e8873d5654f910e86391ba0c30988588b28393e3e8873d5654f910e86391ba
linuxlinux>= 04e906839a053f092ef53f4fb2d610983412b904 < fd9ee3f0d6a53844f65efde581c91bbb0ff749acfd9ee3f0d6a53844f65efde581c91bbb0ff749ac
linuxlinux>= 04e906839a053f092ef53f4fb2d610983412b904 < 51de3600093429e3b712e5f091d767babc5dd6df51de3600093429e3b712e5f091d767babc5dd6df
linuxlinux>= 1e44ee6cdd123d6cfe78b4a94e1572e23bbb58ce < acacd48a37b52fc95f621765762c04152b58d642acacd48a37b52fc95f621765762c04152b58d642
linuxlinux>= 5.15.168 < 5.15.1805.15.180
linuxlinux>= 6.1.113 < 6.1.1346.1.134
linuxlinux>= 6.10.13 < 6.116.11
linuxlinux>= 6.11.2 < 6.126.12
linuxlinux>= 6.6.54 < 6.6.876.6.87
linuxlinux>= 869caa8de8cb94514df704ccbe0b024fda4b9398 < 0f10f83acfd619e13c64d6705908dfd792f195440f10f83acfd619e13c64d6705908dfd792f19544
linuxlinux>= b80aacfea6e8d6ed6e430aa13922d6ccf044415a < 95789c2f94fd29dce8759f9766baa333f749287c95789c2f94fd29dce8759f9766baa333f749287c
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-86.876.8.0-86.87
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 5.15.168 < 5.15.1805.15.180
linuxlinux_kernel>= 6.1.113 < 6.1.1346.1.134

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.