CVE-2025-22047

MEDIUM

Linux Kernel - Incorrect Return Value Handling in __apply_microcode_amd()

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: x86/microcode/AMD: Fix __apply_microcode_amd()'s return value When verify_sha256_digest() fails, __apply_microcode_amd() should propagate the failure by returning false (and not -1 which is promoted to true).

Scores

CVSS v3 5.5
EPSS 0.0019
EPSS Percentile 8.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (22)
linux/Kernel < 6.6.87linux
linux/Kernel 6.13.0 - 6.13.11linux
linux/Kernel 6.14.0 - 6.14.2linux
linux/Kernel 6.7.0 - 6.12.23linux
Linux/Linux < 6.14
Linux/Linux 3e8653e399e7111a3e87d534ff4533b250ae574f - ada88219d5315fc13f2910fe278c7112d8d68889
Linux/Linux 50cef76d5cb0e199cda19f026842560f6eedc4f7 - 31ab12df723543047c3fc19cb8f8c4498ec6267f
Linux/Linux 50cef76d5cb0e199cda19f026842560f6eedc4f7 - 7f705a45f130a85fbf31c2abdc999c65644c8307
Linux/Linux 6.12.18 - 6.12.23
Linux/Linux 6.12.23 - 6.12.*
... and 12 more
Published Apr 16, 2025
Tracked Since Feb 18, 2026