CVE-2025-22092NULL Pointer Dereference in Linux

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 78.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 16
Latest updateJul 8

Description

In the Linux kernel, the following vulnerability has been resolved: PCI: Fix NULL dereference in SR-IOV VF creation error path Clean up when virtfn setup fails to prevent NULL pointer dereference during device removal. The kernel oops below occurred due to incorrect error handling flow when pci_setup_device() fails. Add pci_iov_scan_device(), which handles virtfn allocation and setup and cleans up if pci_setup_device() fails, so pci_iov_add_virtfn() doesn't need to call pci_stop_and_remove_bu

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDlinux/linux_kernel6.136.13.11+1
Debianlinux/linux_kernel< 6.16.3-1
Ubuntulinux/linux_kernel< 6.14.0-22.22
CVEListV5linux/linuxe3f30d563a388220a7c4e3b9a7b52ac0b0324b26ef421b4d206f0d3681804b8f94f06a8458a53aaf+3
debiandebian/linux

Patches

🔴Vulnerability Details

5
OSV
linux-aws, linux-oracle vulnerabilities2025-07-08
OSV
linux-azure vulnerabilities2025-06-26
OSV
linux, linux-gcp, linux-raspi, linux-realtime vulnerabilities2025-06-24
OSV
CVE-2025-22092: In the Linux kernel, the following vulnerability has been resolved: PCI: Fix NULL dereference in SR-IOV VF creation error path Clean up when virtfn se2025-04-16
GHSA
GHSA-83jq-f5p9-r6x4: In the Linux kernel, the following vulnerability has been resolved: PCI: Fix NULL dereference in SR-IOV VF creation error path Clean up when virtfn2025-04-16

📋Vendor Advisories

5
Ubuntu
Linux kernel vulnerabilities2025-07-08
Ubuntu
Linux kernel (Azure) vulnerabilities2025-06-26
Ubuntu
Linux kernel vulnerabilities2025-06-24
Red Hat
kernel: PCI: Fix NULL dereference in SR-IOV VF creation error path2025-04-16
Debian
CVE-2025-22092: linux - In the Linux kernel, the following vulnerability has been resolved: PCI: Fix NU...2025
CVE-2025-22092 — NULL Pointer Dereference in Linux | cvebase