CVE-2025-22004: Linux Kernel

High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: net: atm: fix use after free in lec_send() The ->send() operation frees skb so save the length before calling ->send() to avoid a use after free.

Affected products

  • Linux Linux Kernel: from 2.6.12, before 6.1.132 (fixed in 6.1.132); from 6.2, before 6.6.85 (fixed in 6.6.85); from 6.7, before 6.12.21 (fixed in 6.12.21); from 6.13, before 6.13.9 (fixed in 6.13.9); version 6.14 only

Published 2025-04-03. Last modified 2026-07-30.