cbcvebase.
CVE-2025-22056
published 2025-04-16

CVE-2025-22056: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix geneve_opt type confusion addition When handling multiple…

PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.5th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_tunnel: fix geneve_opt type confusion addition When handling multiple NFTA_TUNNEL_KEY_OPTS_GENEVE attributes, the parsing logic should place every geneve_opt structure one by one compactly. Hence, when deciding the next geneve_opt position, the pointer addition should be in units of char *. However, the current implementation erroneously does type conversion before the addition, which will lead to heap out-of-bounds write. [ 6.989857] ================================================================== [ 6.990293] BUG: KASAN: slab-out-of-bounds in nft_tunnel_obj_init+0x977/0xa70 [ 6.990725] Write of size 124 at addr ffff888005f18974 by task poc/178 [ 6.991162] [ 6.991259] CPU: 0 PID: 178 Comm: poc-oob-write Not tainted 6.1.132 #1 [ 6.991655] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.0-0-gd239552ce722-prebuilt.qemu.org 04/01/2014 [ 6.992281] Call Trace: [ 6.992423] [ 6.992586] dump_stack_lvl+0x44/0x5c [ 6.992801] print_report+0x184/0x4be [ 6.993790] kasan_report+0xc5/0x100 [ 6.994252] kasan_check_range+0xf3/0x1a0 [ 6.994486] memcpy+0x38/0x60 [ 6.994692] nft_tunnel_obj_init+0x977/0xa70 [ 6.995677] nft_obj_init+0x10c/0x1b0 [ 6.995891] nf_tables_newobj+0x585/0x950 [ 6.996922] nfnetlink_rcv_batch+0xdf9/0x1020 [ 6.998997] nfnetlink_rcv+0x1df/0x220 [ 6.999537] netlink_unicast+0x395/0x530 [ 7.000771] netlink_sendmsg+0x3d0/0x6d0 [ 7.001462] __sock_sendmsg+0x99/0xa0 [ 7.001707] ____sys_sendmsg+0x409/0x450 [ 7.002391] ___sys_sendmsg+0xfd/0x170 [ 7.003145] __sys_sendmsg+0xea/0x170 [ 7.004359] do_syscall_64+0x5e/0x90 [ 7.005817] entry_SYSCALL_64_after_hwframe+0x6e/0xd8 [ 7.006127] RIP: 0033:0x7ec756d4e407 [ 7.006339] Code: 48 89 fa 4c 89 df e8 38 aa 00 00 8b 93 08 03 00 00 59 5e 48 83 f8 fc 74 1a 5b c3 0f 1f 84 00 00 00 00 00 48 8b 44 24 10 0f 05 c3 0f 1f 80 00 00 00 00 83 e2 39 83 faf [ 7.007364] RSP: 002b:00007ffed5d46760 EFLAGS: 00000202 ORIG_RAX: 000000000000002e [

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 925d844696d9287f841d6b3e0ed62a35fb175970 < 31d49eb436f2da61280508d7adf8c9b473b967aa31d49eb436f2da61280508d7adf8c9b473b967aa
linuxlinux>= 925d844696d9287f841d6b3e0ed62a35fb175970 < ca2adfc03cd6273f0b589fe65afc6f75e0fe116eca2adfc03cd6273f0b589fe65afc6f75e0fe116e
linuxlinux>= 925d844696d9287f841d6b3e0ed62a35fb175970 < a263d31c8c92e5919d41af57d9479cfb66323782a263d31c8c92e5919d41af57d9479cfb66323782
linuxlinux>= 925d844696d9287f841d6b3e0ed62a35fb175970 < 28d88ee1e1cc8ac2d79aeb112717b97c5c833d4328d88ee1e1cc8ac2d79aeb112717b97c5c833d43
linuxlinux>= 925d844696d9287f841d6b3e0ed62a35fb175970 < 0a93a710d6df334b828ea064c6d39fda34f901dc0a93a710d6df334b828ea064c6d39fda34f901dc
linuxlinux>= 925d844696d9287f841d6b3e0ed62a35fb175970 < 446d94898c560ed2f61e26ae445858a4c4830762446d94898c560ed2f61e26ae445858a4c4830762
linuxlinux>= 925d844696d9287f841d6b3e0ed62a35fb175970 < 708e268acb3a446ad2a8a3d2e9bd41cc23660cd6708e268acb3a446ad2a8a3d2e9bd41cc23660cd6
linuxlinux>= 925d844696d9287f841d6b3e0ed62a35fb175970 < 1b755d8eb1ace3870789d48fbd94f386ad6e30be1b755d8eb1ace3870789d48fbd94f386ad6e30be
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-86.876.8.0-86.87
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 5.11 < 5.15.1805.15.180
linuxlinux_kernel>= 5.16 < 6.1.1346.1.134
linuxlinux_kernel>= 5.7 < 5.10.2365.10.236
linuxlinux_kernel>= 6.13 < 6.13.116.13.11
linuxlinux_kernel>= 6.14 < 6.14.26.14.2
linuxlinux_kernel>= 6.2 < 6.6.876.6.87
linuxlinux_kernel>= 6.7 < 6.12.236.12.23

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.