CVE-2025-22088

Source
https://cve.org/CVERecord?id=CVE-2025-22088
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-22088.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-22088
Downstream
Related
Published
2025-04-16T14:12:41.065Z
Modified
2026-05-07T04:17:37.506459Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
RDMA/erdma: Prevent use-after-free in erdma_accept_newconn()
Details

In the Linux kernel, the following vulnerability has been resolved:

RDMA/erdma: Prevent use-after-free in erdmaacceptnewconn()

After the erdmacepput(newcep) being called, newcep will be freed, and the following dereference will cause a UAF problem. Fix this issue.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/22xxx/CVE-2025-22088.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
920d93eac8b97778fef48f34f10e58ddf870fc2a
Fixed
bc1db4d8f1b0dc480d7d745a60a8cc94ce2badd4
Fixed
667a628ab67d359166799fad89b3c6909599558a
Fixed
a114d25d584c14019d31dbf2163780c47415a187
Fixed
78411a133312ce7d8a3239c76a8fd85bca1cc10f
Fixed
7aa6bb5276d9fec98deb05615a086eeb893854ad
Fixed
83437689249e6a17b25e27712fbee292e42e7855

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-22088.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.0.0
Fixed
6.1.134
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.87
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.23
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.13.11
Type
ECOSYSTEM
Events
Introduced
6.14.0
Fixed
6.14.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-22088.json"