CVE-2025-22033

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Apr 16, 2025
Updated: Apr 29, 2025
CWE ID 476

Summary

[CVE-2025-22033]: A vulnerability in the Linux kernel, specifically in the do_compat_alignment_fixup() function, has been addressed. This issue occurs when the function returns NULL after do_alignment_t32_to_handler() fails to fix up alignment faults for certain instructions. If this happens, the kernel will panic due to a NULL pointer dereference. Without the patch, this results in an internal error, as evidenced by the provided stack trace. The bug affects the Debian 6.1.128-1 distribution, and modules such as igb, i2c, and xhci_hcd are among those linked in.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share