CVE-2025-22088

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Apr 16, 2025
Updated: Apr 25, 2025
CWE ID 416

Summary

CVE-2025-22088 is a newly discovered vulnerability affecting the Linux kernel. This issue involves the RDMA/erdma subsystem, specifically in the function erdma_accept_newconn(). After the call to erdma_cep_put(new_cep), the new_cep variable is freed, leading to a use-after-free condition. Subsequent dereferences of the freed memory can result in a User After Free (UAF) problem. This vulnerability has been addressed in recent Linux kernel updates.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share