CVE-2025-22097

HIGH

Linux Kernel 5.12-6.14.2 - Use-After-Free in vkms Driver Initialization

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Fix use after free and double free on init error If the driver initialization fails, the vkms_exit() function might access an uninitialized or freed default_config pointer and it might double free it. Fix both possible errors by initializing default_config only when the driver initialization succeeded.

Scores

CVSS v3 7.8
EPSS 0.0017
EPSS Percentile 6.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (23)
linux/Kernel 5.12.0 - 5.15.180linux
linux/Kernel 5.16.0 - 6.1.134linux
linux/Kernel 6.13.0 - 6.13.11linux
linux/Kernel 6.14.0 - 6.14.2linux
linux/Kernel 6.2.0 - 6.6.87linux
linux/Kernel 6.7.0 - 6.12.23linux
Linux/Linux < 5.12
Linux/Linux 2df7af93fdadb9ba8226fe443fae15ecdefda2a6 - 1f68f1cf09d06061eb549726ff8339e064eddebd
Linux/Linux 2df7af93fdadb9ba8226fe443fae15ecdefda2a6 - 49a69f67f53518bdd9b7eeebf019a2da6cc0e954
Linux/Linux 2df7af93fdadb9ba8226fe443fae15ecdefda2a6 - 561fc0c5cf41f646f3e9e61784cbc0fc832fb936
... and 13 more
Published Apr 16, 2025
Tracked Since Feb 18, 2026