cbcvebase.
CVE-2025-22095
published 2025-04-16

CVE-2025-22095: In the Linux kernel, the following vulnerability has been resolved: PCI: brcmstb: Fix error path after a call to regulator_bulk_get() If the…

PriorityP416medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
9.0th percentile
In the Linux kernel, the following vulnerability has been resolved: PCI: brcmstb: Fix error path after a call to regulator_bulk_get() If the regulator_bulk_get() returns an error and no regulators are created, we need to set their number to zero. If we don't do this and the PCIe link up fails, a call to the regulator_bulk_free() will result in a kernel panic. While at it, print the error value, as we cannot return an error upwards as the kernel will WARN() on an error from add_bus(). [kwilczynski: commit log, use comma in the message to match style with other similar messages]

Affected

19 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 9e6be018b26347c26a93e63fb50a37ee2c9311de < 99a0efba9f903acbdece548862b6b4cbe7d999e199a0efba9f903acbdece548862b6b4cbe7d999e1
linuxlinux>= 9e6be018b26347c26a93e63fb50a37ee2c9311de < eedd054834930b8d678f0776cd4b091b8fffbb4aeedd054834930b8d678f0776cd4b091b8fffbb4a
linuxlinux>= 9e6be018b26347c26a93e63fb50a37ee2c9311de < df63321a40cc98e52313cffbff376b8ae9ceffa7df63321a40cc98e52313cffbff376b8ae9ceffa7
linuxlinux>= 9e6be018b26347c26a93e63fb50a37ee2c9311de < 7842e842a9bf6bd5866c84f588353711d131ab1a7842e842a9bf6bd5866c84f588353711d131ab1a
linuxlinux>= 9e6be018b26347c26a93e63fb50a37ee2c9311de < 6f44e1fdb006db61394aa4d4c25728ada00842e76f44e1fdb006db61394aa4d4c25728ada00842e7
linuxlinux>= 9e6be018b26347c26a93e63fb50a37ee2c9311de < 3651ad5249c51cf7eee078e12612557040a6bdb43651ad5249c51cf7eee078e12612557040a6bdb4
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.8.0-86.876.8.0-86.87
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.0 < 6.1.1346.1.134
linuxlinux_kernel>= 6.13 < 6.13.116.13.11
linuxlinux_kernel>= 6.14 < 6.14.26.14.2
linuxlinux_kernel>= 6.2 < 6.6.876.6.87
linuxlinux_kernel>= 6.7 < 6.12.236.12.23

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.1HIGH
vendor_ubuntu7.1HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.