CVE-2025-22002

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 3, 2025
Updated: Apr 10, 2025
CWE ID 476

Summary

CVE-2025-22002: A vulnerability in Linux kernel's netfs component has been identified and addressed. When writing to the cache fails on certain filesystems like NFS and Ceph, which do not implement the `invalidate_cache` method, the kernel crashes due to a NULL pointer dereference. This issue can lead to system instability and potential security vulnerabilities. The patch for this vulnerability adds the necessary `NULL` check to prevent such crashes and ensure system stability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share