cbcvebase.
CVE-2025-22071
published 2025-04-16

CVE-2025-22071: In the Linux kernel, the following vulnerability has been resolved: spufs: fix a leak in spufs_create_context() Leak fixes back in 2008 missed one case - if we…

PriorityP417medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.20%
9.9th percentile
In the Linux kernel, the following vulnerability has been resolved: spufs: fix a leak in spufs_create_context() Leak fixes back in 2008 missed one case - if we are trying to set affinity and spufs_mkdir() fails, we need to drop the reference to neighbor.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 58119068cb27ef7513f80aff44b62a3a8f40ef5f < 829bd6139968e2e759f3928cf65ad0db1e302fe3829bd6139968e2e759f3928cf65ad0db1e302fe3
linuxlinux>= 58119068cb27ef7513f80aff44b62a3a8f40ef5f < 410c787d89c92df4215d7b1a338e2c1a8aba6b9b410c787d89c92df4215d7b1a338e2c1a8aba6b9b
linuxlinux>= 58119068cb27ef7513f80aff44b62a3a8f40ef5f < c4e72a0d75442237b6f3bcca10a7d81b89376d16c4e72a0d75442237b6f3bcca10a7d81b89376d16
linuxlinux>= 58119068cb27ef7513f80aff44b62a3a8f40ef5f < a333f223e555d27609f8b45d75a08e8e1d36c432a333f223e555d27609f8b45d75a08e8e1d36c432
linuxlinux>= 58119068cb27ef7513f80aff44b62a3a8f40ef5f < 239ea3c34673b3244a499fd65771c47e5bffcbb0239ea3c34673b3244a499fd65771c47e5bffcbb0
linuxlinux>= 58119068cb27ef7513f80aff44b62a3a8f40ef5f < d04600f43569d48262e1328eaa1592fcefa2c19cd04600f43569d48262e1328eaa1592fcefa2c19c
linuxlinux>= 58119068cb27ef7513f80aff44b62a3a8f40ef5f < 5a90b699844a5bb96961e5892e51cc59255444a35a90b699844a5bb96961e5892e51cc59255444a3
linuxlinux>= 58119068cb27ef7513f80aff44b62a3a8f40ef5f < 4a7448c83e117ed68597952ecaede1cebc4427a74a7448c83e117ed68597952ecaede1cebc4427a7
linuxlinux>= 58119068cb27ef7513f80aff44b62a3a8f40ef5f < 0f5cce3fc55b08ee4da3372baccf4bcd36a983960f5cce3fc55b08ee4da3372baccf4bcd36a98396
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-86.876.8.0-86.87
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 0 < 5.4.0-218.2385.4.0-218.238
linuxlinux_kernel>= 2.6.25 < 5.4.2925.4.292
linuxlinux_kernel>= 5.11 < 5.15.1805.15.180
linuxlinux_kernel>= 5.16 < 6.1.1346.1.134
linuxlinux_kernel>= 5.5 < 5.10.2365.10.236
linuxlinux_kernel>= 6.13 < 6.13.116.13.11
linuxlinux_kernel>= 6.14 < 6.14.26.14.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.