cbcvebase.
CVE-2025-22086
published 2025-04-16

CVE-2025-22086: In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow When cur_qp isn't NULL, in order to avoid…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.29%
21.4th percentile
In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow When cur_qp isn't NULL, in order to avoid fetching the QP from the radix tree again we check if the next cqe QP is identical to the one we already have. The bug however is that we are checking if the QP is identical by checking the QP number inside the CQE against the QP number inside the mlx5_ib_qp, but that's wrong since the QP number from the CQE is from FW so it should be matched against mlx5_core_qp which is our FW QP number. Otherwise we could use the wrong QP when handling a CQE which could cause the kernel trace below. This issue is mainly noticeable over QPs 0 & 1, since for now they are the only QPs in our driver whereas the QP number inside mlx5_ib_qp doesn't match the QP number inside mlx5_core_qp. BUG: kernel NULL pointer dereference, address: 0000000000000012 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: Oops: 0000 [#1] SMP CPU: 0 UID: 0 PID: 7927 Comm: kworker/u62:1 Not tainted 6.14.0-rc3+ #189 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.16.3-0-ga6ed6b701f0a-prebuilt.qemu.org 04/01/2014 Workqueue: ib-comp-unb-wq ib_cq_poll_work [ib_core] RIP: 0010:mlx5_ib_poll_cq+0x4c7/0xd90 [mlx5_ib] Code: 03 00 00 8d 58 ff 21 cb 66 39 d3 74 39 48 c7 c7 3c 89 6e a0 0f b7 db e8 b7 d2 b3 e0 49 8b 86 60 03 00 00 48 c7 c7 4a 89 6e a0 b7 5c 98 02 e8 9f d2 b3 e0 41 0f b7 86 78 03 00 00 83 e8 01 21 RSP: 0018:ffff88810511bd60 EFLAGS: 00010046 RAX: 0000000000000010 RBX: 0000000000000000 RCX: 0000000000000000 RDX: 0000000000000000 RSI: ffff88885fa1b3c0 RDI: ffffffffa06e894a RBP: 00000000000000b0 R08: 0000000000000000 R09: ffff88810511bc10 R10: 0000000000000001 R11: 0000000000000001 R12: ffff88810d593000 R13: ffff88810e579108 R14: ffff888105146000 R15: 00000000000000b0 FS: 0000000000000000(0000) GS:ffff88885fa00000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 00000

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c < 3b97d77049856865ac5ce8ffbc6e716928310f7f3b97d77049856865ac5ce8ffbc6e716928310f7f
linuxlinux>= e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c < 856d9e5d72dc44eca6d5a153581c58fbd84e92e1856d9e5d72dc44eca6d5a153581c58fbd84e92e1
linuxlinux>= e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c < f0447ceb8a31d79bee7144f98f9a13f765531e1af0447ceb8a31d79bee7144f98f9a13f765531e1a
linuxlinux>= e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c < dc7139b7031d877acd73d7eff55670f22f48cd5edc7139b7031d877acd73d7eff55670f22f48cd5e
linuxlinux>= e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c < 7c51a6964b45b6d40027abd77e89cef30d26dc5a7c51a6964b45b6d40027abd77e89cef30d26dc5a
linuxlinux>= e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c < cad677085274ecf9c7565b5bfc5d2e49acbf174ccad677085274ecf9c7565b5bfc5d2e49acbf174c
linuxlinux>= e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c < 55c65a64aefa6267b964d90e9a4039cb68ec73a555c65a64aefa6267b964d90e9a4039cb68ec73a5
linuxlinux>= e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c < d52636eb13ccba448a752964cc6fc49970912874d52636eb13ccba448a752964cc6fc49970912874
linuxlinux>= e126ba97dba9edeb6fafa3665b5f8497fc9cdf8c < 5ed3b0cb3f827072e93b4c5b6e2b8106fd7cccbd5ed3b0cb3f827072e93b4c5b6e2b8106fd7cccbd
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-142.1525.15.0-142.152
linuxlinux_kernel>= 0 < 6.8.0-86.876.8.0-86.87
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 0 < 5.4.0-218.2385.4.0-218.238
linuxlinux_kernel>= 3.11 < 5.4.2925.4.292
linuxlinux_kernel>= 5.11 < 5.15.1805.15.180
linuxlinux_kernel>= 5.16 < 6.1.1346.1.134
linuxlinux_kernel>= 5.5 < 5.10.2365.10.236
linuxlinux_kernel>= 6.13 < 6.13.116.13.11

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.