Buffer overflow in Linux kernel - CVE-2025-22026

 

Buffer overflow in Linux kernel - CVE-2025-22026

Published: April 22, 2025 / Updated: May 10, 2025


Vulnerability identifier: #VU107793
CSH Severity: Low
CVSS v4 BT: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-22026
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory corruption within the nfsd_show() function in fs/nfsd/stats.c, within the nfsd_net_init() function in fs/nfsd/nfsctl.c. A local user can perform a denial of service (DoS) attack.


Affected software

Linux kernel
Debian Linux
Anolis OS
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
openEuler
Ubuntu
Netezza Appliance
Juniper Secure Analytics (JSA)
IBM Qradar SIEM
BIG-IQ Centralized Management
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
kernel-rt (Red Hat package)
kernel (Red Hat package)
kernel-debug-core
python3-perf
kernel-doc
kernel-abi-stablelists
bpftool
kernel
kernel-core
kernel-cross-headers
kernel-debug
perf
kernel-debug-devel
kernel-debug-modules
kernel-debug-modules-extra
kernel-devel
kernel-headers
kernel-modules
kernel-modules-extra
kernel-tools
kernel-tools-libs
kernel-tools-libs-devel
kernel-tools-devel
kernel-tools-debuginfo
kernel-debuginfo
kernel-debugsource
kernel-source
python3-perf-debuginfo
perf-debuginfo
bpftool-debuginfo
linux (Debian package)
kernel-extra-modules
linux (Ubuntu package)
linux-aws-fips (Ubuntu package)
linux-lowlatency (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-xilinx (Ubuntu package)
linux-aws (Ubuntu package)
linux-gcp (Ubuntu package)
linux-ibm (Ubuntu package)
linux-nvidia-lowlatency (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-gcp-fips (Ubuntu package)
linux-gcp-6.8 (Ubuntu package)
linux-azure-6.8 (Ubuntu package)
linux-raspi-realtime (Ubuntu package)
linux-realtime-6.8 (Ubuntu package)
BIG-IP

How to mitigate CVE-2025-22026

Install update from vendor's website.

Linux kernel - update to 6.13.12
Netezza Appliance - update to 1.0.1.0 fp278500
Juniper Secure Analytics (JSA) - update to 7.5.0 UP14 IF01
IBM Qradar SIEM - update to 7.5.0 Update Pack 14 IF01
kernel-rt (Red Hat package) - addressed in versions 3.10.0-1160.142.1.rt56.1294.el7, 4.18.0-553.77.1.rt7.418.el8_10, 5.14.0-70.144.1.rt21.216.el9_0, 5.14.0-284.131.1.rt14.416.el9_2
kernel (Red Hat package) - addressed in versions 4.18.0-193.173.1.el8_2, 4.18.0-305.179.1.el8_4, 4.18.0-372.166.1.el8_6, 4.18.0-477.116.1.el8_8, 5.14.0-70.144.1.el9_0, 5.14.0-284.131.1.el9_2, 5.14.0-570.55.1.el9_6, 6.12.0-55.38.1.el10_0
kernel-debug-core - update to 4.18.0-553.78.1.0.1
python3-perf - update to 4.18.0-553.78.1.0.1
kernel-doc - update to 4.18.0-553.78.1.0.1
kernel-abi-stablelists - update to 4.18.0-553.78.1.0.1
bpftool - update to 4.18.0-553.78.1.0.1
kernel - update to 4.18.0-553.78.1.0.1
kernel-core - update to 4.18.0-553.78.1.0.1
kernel-cross-headers - update to 4.18.0-553.78.1.0.1
kernel-debug - update to 4.18.0-553.78.1.0.1
perf - update to 4.18.0-553.78.1.0.1
kernel-debug-devel - update to 4.18.0-553.78.1.0.1
kernel-debug-modules - update to 4.18.0-553.78.1.0.1
kernel-debug-modules-extra - update to 4.18.0-553.78.1.0.1
kernel-devel - update to 4.18.0-553.78.1.0.1
kernel-headers - update to 4.18.0-553.78.1.0.1
kernel-modules - update to 4.18.0-553.78.1.0.1
kernel-modules-extra - update to 4.18.0-553.78.1.0.1
kernel-tools - update to 4.18.0-553.78.1.0.1
kernel-tools-libs - update to 4.18.0-553.78.1.0.1
kernel-tools-libs-devel - update to 4.18.0-553.78.1.0.1
kernel-tools-devel - addressed in versions 5.10.0-270.0.0.172, 5.10.0-270.0.0.173, 6.6.0-125.0.0.125, 6.6.0-127.0.0.113, 6.6.0-127.0.0.125
kernel-tools-debuginfo - addressed in versions 5.10.0-270.0.0.172, 5.10.0-270.0.0.173, 6.6.0-125.0.0.125, 6.6.0-127.0.0.113, 6.6.0-127.0.0.125
kernel - addressed in versions 5.10.0-270.0.0.172, 5.10.0-270.0.0.173, 6.6.0-125.0.0.125, 6.6.0-127.0.0.113, 6.6.0-127.0.0.125
kernel-debuginfo - addressed in versions 5.10.0-270.0.0.172, 5.10.0-270.0.0.173, 6.6.0-125.0.0.125, 6.6.0-127.0.0.113, 6.6.0-127.0.0.125
kernel-debugsource - addressed in versions 5.10.0-270.0.0.172, 5.10.0-270.0.0.173, 6.6.0-125.0.0.125, 6.6.0-127.0.0.113, 6.6.0-127.0.0.125
kernel-devel - addressed in versions 5.10.0-270.0.0.172, 5.10.0-270.0.0.173, 6.6.0-125.0.0.125, 6.6.0-127.0.0.113, 6.6.0-127.0.0.125
kernel-headers - addressed in versions 5.10.0-270.0.0.172, 5.10.0-270.0.0.173, 6.6.0-125.0.0.125, 6.6.0-127.0.0.113, 6.6.0-127.0.0.125
kernel-source - addressed in versions 5.10.0-270.0.0.172, 5.10.0-270.0.0.173, 6.6.0-125.0.0.125, 6.6.0-127.0.0.113, 6.6.0-127.0.0.125
kernel-tools - addressed in versions 5.10.0-270.0.0.172, 5.10.0-270.0.0.173, 6.6.0-125.0.0.125, 6.6.0-127.0.0.113, 6.6.0-127.0.0.125
python3-perf-debuginfo - addressed in versions 5.10.0-270.0.0.172, 5.10.0-270.0.0.173, 6.6.0-125.0.0.125, 6.6.0-127.0.0.113, 6.6.0-127.0.0.125
python3-perf - addressed in versions 5.10.0-270.0.0.172, 5.10.0-270.0.0.173, 6.6.0-125.0.0.125, 6.6.0-127.0.0.113, 6.6.0-127.0.0.125
perf-debuginfo - addressed in versions 5.10.0-270.0.0.172, 5.10.0-270.0.0.173, 6.6.0-125.0.0.125, 6.6.0-127.0.0.113, 6.6.0-127.0.0.125
perf - addressed in versions 5.10.0-270.0.0.172, 5.10.0-270.0.0.173, 6.6.0-125.0.0.125, 6.6.0-127.0.0.113, 6.6.0-127.0.0.125
bpftool - addressed in versions 5.10.0-270.0.0.173, 6.6.0-125.0.0.125, 6.6.0-127.0.0.113, 6.6.0-127.0.0.125
bpftool-debuginfo - addressed in versions 5.10.0-270.0.0.173, 6.6.0-125.0.0.125, 6.6.0-127.0.0.113, 6.6.0-127.0.0.125
linux (Debian package) - update to 6.1.164-1
kernel-extra-modules - update to 6.6.0-125.0.0.125
linux (Ubuntu package) - addressed in versions 6.8.0-100.100, 6.8.0-1047.51, 6.14.0-22.22, 6.14.0-1004.4, 6.14.0-1007.7, 6.14.0-1008.8
linux-aws-fips (Ubuntu package) - addressed in versions 6.8.0-100.100+fips1, 6.8.0-1046.49+fips1
linux-lowlatency (Ubuntu package) - update to 6.8.0-100.100.1
linux-hwe-6.8 (Ubuntu package) - addressed in versions 6.8.0-100.100.1~22.04.1, 6.8.0-100.100~22.04.1
linux-xilinx (Ubuntu package) - addressed in versions 6.8.0.1023.24, 6.8.0-1023.24
linux-aws (Ubuntu package) - addressed in versions 6.8.0-1030.33, 6.8.0-1043.44, 6.8.0-1043.44~22.04.1, 6.8.0-1046.49~22.04.1, 6.14.0-1007.7, 6.14.0-1007.7+1
linux-gcp (Ubuntu package) - addressed in versions 6.8.0-1043.48, 6.8.0-1047.50~22.04.2
linux-ibm (Ubuntu package) - addressed in versions 6.8.0-1044.44, 6.8.0-1044.44~22.04.1
linux-nvidia-lowlatency (Ubuntu package) - update to 6.8.0-1046.49.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1046.52, 6.14.0-1007.7
linux-azure-fips (Ubuntu package) - update to 6.8.0-1046.52+fips1
linux-gcp-fips (Ubuntu package) - update to 6.8.0-1047.50+fips1
linux-gcp-6.8 (Ubuntu package) - update to 6.8.0-1047.50~22.04.2
linux-azure-6.8 (Ubuntu package) - update to 6.8.0-1051.57~22.04.1
linux-raspi-realtime (Ubuntu package) - addressed in versions 6.8.0-2037.38, 6.8.1-1041.42
linux-realtime-6.8 (Ubuntu package) - update to 6.8.1-1041.42~22.04.1

External References

Related Security Bulletins