SB2025042287 - NULL pointer dereference in Linux kernel infiniband core driver
Published: April 22, 2025 Updated: May 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2025-22089)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the ib_setup_device_attrs() function in drivers/infiniband/core/sysfs.c, within the rdma_init_coredev() function in drivers/infiniband/core/device.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0cf80f924aecb5b2bebd4f4ad11b2efc676a0b78
- https://git.kernel.org/stable/c/6682da5d8fd578a5068531d01633c9d2e4c8f12b
- https://git.kernel.org/stable/c/9a5b7f8842a90a5e6eeff37f9f6d814e61ea3529
- https://git.kernel.org/stable/c/a1ecb30f90856b0be4168ad51b8875148e285c1f
- https://git.kernel.org/stable/c/c14d9704f5d77a7c7fa46e2114b64a4f75b64e17
- https://git.kernel.org/stable/c/d5212b99649c5740154f307e9e3d7fee9bf62773
- https://git.kernel.org/stable/c/df45ae2a4f1cdfda00c032839e12092e1f32c05e
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.23