CVE-2025-22078

In the Linux kernel, the following vulnerability has been resolved: staging: vchiq_arm: Fix possible NPR of keep-alive thread In case vchiq_platform_conn_state_changed() is never called or fails before driver removal, ka_thread won't be a valid pointer to a task_struct. So do the necessary checks before calling kthread_stop to avoid a crash.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

31 Oct 2025, 20:45

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/1817c4b85011998604e5ff9a80a6e01adb7e7e81 - () https://git.kernel.org/stable/c/1817c4b85011998604e5ff9a80a6e01adb7e7e81 - Patch
References () https://git.kernel.org/stable/c/3db89bc6d973e2bcaa852f6409c98c228f39a926 - () https://git.kernel.org/stable/c/3db89bc6d973e2bcaa852f6409c98c228f39a926 - Patch
References () https://git.kernel.org/stable/c/a915c896f95a989a7759a73f8c064f5dc3775175 - () https://git.kernel.org/stable/c/a915c896f95a989a7759a73f8c064f5dc3775175 - Patch
References () https://git.kernel.org/stable/c/bd38395b901327f77a82112f006240de22cf2ceb - () https://git.kernel.org/stable/c/bd38395b901327f77a82112f006240de22cf2ceb - Patch
Summary
  • (es) En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: staging: vchiq_arm: Se corrige un posible NPR del subproceso keep-alive. Si vchiq_platform_conn_state_changed() no se llama nunca o falla antes de la eliminación del controlador, ka_thread no será un puntero válido a una task_struct. Por lo tanto, realice las comprobaciones necesarias antes de llamar a kthread_stop para evitar un bloqueo.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
First Time Linux linux Kernel
Linux

16 Apr 2025, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-16 15:16

Updated : 2025-10-31 20:45


NVD link : CVE-2025-22078

Mitre link : CVE-2025-22078

CVE.ORG link : CVE-2025-22078


JSON object : View

Products Affected

linux

  • linux_kernel