CVE-2025-22016: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: dpll: fix xa_alloc_cyclic() error handling In case of returning 1 from xa_alloc_cyclic() (wrapping) ERR_PTR(1) will be returned, which will cause IS_ERR() to be false. Which can lead to dereference not allocated pointer (pin). Fix it by checking if err is lower than zero. This wasn't found in real usecase, only noticed. Credit to Pierre.
Affected products
- Linux Linux Kernel: from 6.8, before 6.12.21 (fixed in 6.12.21); from 6.13, before 6.13.9 (fixed in 6.13.9); version 6.14 only
Published 2025-04-08. Last modified 2026-06-17.