CVE-2025-22001: Linux Kernel

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Fix integer overflow in qaic_validate_req() These are u64 variables that come from the user via qaic_attach_slice_bo_ioctl(). Use check_add_overflow() to ensure that the math doesn't have an integer wrapping bug.

Affected products

  • Linux Linux Kernel: from 6.4, before 6.6.85 (fixed in 6.6.85); from 6.7, before 6.12.21 (fixed in 6.12.21); from 6.13, before 6.13.9 (fixed in 6.13.9); version 6.14 only

Published 2025-04-03. Last modified 2026-07-30.