#VU107763 Buffer overflow in Linux kernel - CVE-2025-22091
Published: April 22, 2025 / Updated: May 10, 2025
Linux kernel
Linux Foundation
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to memory corruption within the create_mkey_callback(), alloc_cacheable_mr(), reg_create() and create_real_mr() functions in drivers/infiniband/hw/mlx5/mr.c. A local user can perform a denial of service (DoS) attack.
Remediation
External links
- https://git.kernel.org/stable/c/01fd737776ca0f17a96d83cd7f0840ce130b9a02
- https://git.kernel.org/stable/c/05b215d5e219c0228b9c7082ba9bcf176c576646
- https://git.kernel.org/stable/c/e0c09f639ca0e102f250df8787740c2013e9d1b3
- https://git.kernel.org/stable/c/f0c2427412b43cdf1b7b0944749ea17ddb97d5a5
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.23
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.13.11
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.14.2