cbcvebase.
CVE-2025-22088
published 2025-04-16

CVE-2025-22088: In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Prevent use-after-free in erdma_accept_newconn() After the…

PriorityP341critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.50%
39.8th percentile
In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Prevent use-after-free in erdma_accept_newconn() After the erdma_cep_put(new_cep) being called, new_cep will be freed, and the following dereference will cause a UAF problem. Fix this issue.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 920d93eac8b97778fef48f34f10e58ddf870fc2a < bc1db4d8f1b0dc480d7d745a60a8cc94ce2badd4bc1db4d8f1b0dc480d7d745a60a8cc94ce2badd4
linuxlinux>= 920d93eac8b97778fef48f34f10e58ddf870fc2a < 667a628ab67d359166799fad89b3c6909599558a667a628ab67d359166799fad89b3c6909599558a
linuxlinux>= 920d93eac8b97778fef48f34f10e58ddf870fc2a < a114d25d584c14019d31dbf2163780c47415a187a114d25d584c14019d31dbf2163780c47415a187
linuxlinux>= 920d93eac8b97778fef48f34f10e58ddf870fc2a < 78411a133312ce7d8a3239c76a8fd85bca1cc10f78411a133312ce7d8a3239c76a8fd85bca1cc10f
linuxlinux>= 920d93eac8b97778fef48f34f10e58ddf870fc2a < 7aa6bb5276d9fec98deb05615a086eeb893854ad7aa6bb5276d9fec98deb05615a086eeb893854ad
linuxlinux>= 920d93eac8b97778fef48f34f10e58ddf870fc2a < 83437689249e6a17b25e27712fbee292e42e785583437689249e6a17b25e27712fbee292e42e7855
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.8.0-63.666.8.0-63.66
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.0 < 6.1.1346.1.134
linuxlinux_kernel>= 6.13 < 6.13.116.13.11
linuxlinux_kernel>= 6.14 < 6.14.26.14.2
linuxlinux_kernel>= 6.2 < 6.6.876.6.87
linuxlinux_kernel>= 6.7 < 6.12.236.12.23
msrcazl3_kernel_6.6.85.1-4_on_azure_linux_3.0
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
ubuntulinux-azure-6.8
ubuntulinux-azure-nvidia

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_ubuntu8.4HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.