CVE-2025-22112: Linux Kernel

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: eth: bnxt: fix out-of-range access of vnic_info array The bnxt_queue_{start | stop}() access vnic_info as much as allocated, which indicates bp->nr_vnics. So, it should not reach bp->vnic_info[bp->nr_vnics].

Affected products

  • Linux Linux Kernel: from 6.12.20, before 6.12.35 (fixed in 6.12.35); from 6.13.8, before 6.14 (fixed in 6.14); version 6.14 only; version 6.14.1 only

Published 2025-04-16. Last modified 2026-06-17.