cbcvebase.
CVE-2025-22064
published 2025-04-16

CVE-2025-22064: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't unregister hook when table is dormant When nf_tables_updchain…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.0th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: don't unregister hook when table is dormant When nf_tables_updchain encounters an error, hook registration needs to be rolled back. This should only be done if the hook has been registered, which won't happen when the table is flagged as dormant (inactive). Just move the assignment into the registration block.

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.25-1 (forky)linux 6.12.25-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 6.3.3 < 6.46.4
linuxlinux>= b9703ed44ffbfba85c103b9de01886a225e14b38 < 6134d1ea1e1408e8e7c8c26545b3b301cbdf1eda6134d1ea1e1408e8e7c8c26545b3b301cbdf1eda
linuxlinux>= b9703ed44ffbfba85c103b9de01886a225e14b38 < feb1fa2a03a27fec7001e93e4223be4120d1784bfeb1fa2a03a27fec7001e93e4223be4120d1784b
linuxlinux>= b9703ed44ffbfba85c103b9de01886a225e14b38 < 03d1fb457b696c18fe15661440c4f052b2374e7e03d1fb457b696c18fe15661440c4f052b2374e7e
linuxlinux>= b9703ed44ffbfba85c103b9de01886a225e14b38 < ce571eba07d54e3637bf334bc48376fbfa55defece571eba07d54e3637bf334bc48376fbfa55defe
linuxlinux>= b9703ed44ffbfba85c103b9de01886a225e14b38 < 688c15017d5cd5aac882400782e7213d40dc3556688c15017d5cd5aac882400782e7213d40dc3556
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.8.0-86.876.8.0-86.87
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.13 < 6.13.116.13.11
linuxlinux_kernel>= 6.14 < 6.14.26.14.2
linuxlinux_kernel>= 6.3.3 < 6.6.876.6.87
linuxlinux_kernel>= 6.7 < 6.12.236.12.23
msrcazl3_kernel_6.6.85.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian5.5LOW
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.