CVE-2025-22026

MEDIUM EPSS 6.5%
Published Apr 16, 20251y ago · Modified Jun 19, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published Apr 16, 2025 1y ago
Last Modified Jun 19, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: nfsd: don't ignore the return code of svc_proc_register() Currently, nfsd_proc_stat_init() ignores the return value of svc_proc_register(). If the procfile creation fails, then the kernel will WARN when it tries to remove the entry later. Fix nfsd_proc_stat_init() to return the same type of pointer as svc_proc_register(), and fix up nfsd_net_init() to check that and fail the nfsd_net construction if it occurs. svc_proc_register() can fail if the dentry can't be allocated, or if an identical dentry already exists. The second case is pretty unlikely in the nfsd_net construction codepath, so if this happens, return -ENOMEM.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
6.5% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-252

Affected Products 3

VendorProductVersionRange
linuxlinux_kernel* <6.12.24
linuxlinux_kernel*≥6.13  –  <6.13.12
linuxlinux_kernel*≥6.14  –  <6.14.2

References 8

  • git.kernel.org https://git.kernel.org/stable/c/30405b23b4d5e2a596fb756d48119d7293194e75
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/51107e768de6821b68aa34a136d07bc7a09cf6c3
  • git.kernel.org https://git.kernel.org/stable/c/51da899c209a9624e48be416bd30e7ed5cd6c3d8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6a59b70fe71ec66c0dd19e2c279c71846a3fb2f0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/930b64ca0c511521f0abdd1d57ce52b2a6e3476b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9d9456185fd5f1891c74354ee297f19538141ead
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e31957a819e60cf0bc9a49408765e6095fd3d046
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e4316bd85e42b01125b2aab691769234a388b8a3

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/30405b23b4d5e2a596fb756d48119d7293194e75
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/51da899c209a9624e48be416bd30e7ed5cd6c3d8
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/6a59b70fe71ec66c0dd19e2c279c71846a3fb2f0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/930b64ca0c511521f0abdd1d57ce52b2a6e3476b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9d9456185fd5f1891c74354ee297f19538141ead
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e31957a819e60cf0bc9a49408765e6095fd3d046
    Patch