cbcvebase.
CVE-2025-22106
published 2025-04-16

CVE-2025-22106: In the Linux kernel, the following vulnerability has been resolved: vmxnet3: unregister xdp rxq info in the reset path vmxnet3 does not unregister xdp rxq info…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.19%
8.8th percentile
In the Linux kernel, the following vulnerability has been resolved: vmxnet3: unregister xdp rxq info in the reset path vmxnet3 does not unregister xdp rxq info in the vmxnet3_reset_work() code path as vmxnet3_rq_destroy() is not invoked in this code path. So, we get below message with a backtrace. Missing unregister, handled but fix driver WARNING: CPU:48 PID: 500 at net/core/xdp.c:182 __xdp_rxq_info_reg+0x93/0xf0 This patch fixes the problem by moving the unregister code of XDP from vmxnet3_rq_destroy() to vmxnet3_rq_cleanup().

Affected

17 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.3-1 (forky)linux 6.16.3-1 (forky)
linuxlinux
linuxlinux>= 54f00cce11786742bd11e5e68c3bf85e6dc048c9 < a6157484bee3385a425d288a69e1eaf03232f5fca6157484bee3385a425d288a69e1eaf03232f5fc
linuxlinux>= 54f00cce11786742bd11e5e68c3bf85e6dc048c9 < 23da4e0bb2a38966d29db0ff90a8fe68fdfa174423da4e0bb2a38966d29db0ff90a8fe68fdfa1744
linuxlinux>= 54f00cce11786742bd11e5e68c3bf85e6dc048c9 < 9908541a9e235b7c5e2fbdd59910eaf9c32c30759908541a9e235b7c5e2fbdd59910eaf9c32c3075
linuxlinux>= 54f00cce11786742bd11e5e68c3bf85e6dc048c9 < 0dd765fae295832934bf28e45dd5a355e0891ed40dd765fae295832934bf28e45dd5a355e0891ed4
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.13 < 6.14.26.14.2
linuxlinux_kernel>= 6.6 < 6.6.1086.6.108
linuxlinux_kernel>= 6.7 < 6.12.496.12.49
msrcazl3_kernel_6.6.104.2-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0
ubuntulinux-xilinx

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_msrc4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.