PT-2025-16695 · Linux+9 · Linux Kernel+9

Published

2025-04-03

·

Updated

2026-04-20

·

CVE-2025-22055

CVSS v2.0

6.2

Medium

VectorAV:L/AC:L/Au:S/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to an integer overflow in the geneve opt length, which can lead to a heap out-of-bounds read. The struct geneve opt uses a 5-bit length for each single option, meaning every variable size option should be smaller than 128 bytes. However, current Netlink policies cannot guarantee this length condition, allowing an attacker to exploit a precisely 128-byte size option to fake a zero-length option and confuse the parsing logic. This can result in a heap out-of-bounds read.
Recommendations To resolve the issue, enforce the correct length condition in related policies. As a temporary workaround, consider restricting access to the vulnerable geneve opt module to minimize the risk of exploitation.

Exploit

Fix

DoS

Out of bounds Read

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:8643
BDU:2025-11892
CVE-2025-22055
DLA-4178-1
DLA-4193-1
DSA-5907-1
ECHO-AB53-5646-6453
INFSA-2025_8643
MGASA-2025-0142
MGASA-2025-0146
OESA-2025-1465
OESA-2025-1878
OESA-2025-1879
OESA-2025-1880
OPENSUSE-SU-2025_01614-1
OPENSUSE-SU-2025_01620-1
OPENSUSE-SU-2025_01627-1
OPENSUSE-SU-2025_01633-1
OPENSUSE-SU-2025_01640-1
OPENSUSE-SU-2025_01707-1
RHSA-2025:8643
RHSA-2025:8669
RHSA-2025_8643
SUSE-SU-2025:01600-1
SUSE-SU-2025:01614-1
SUSE-SU-2025:01620-1
SUSE-SU-2025:01627-1
SUSE-SU-2025:01633-1
SUSE-SU-2025:01640-1
SUSE-SU-2025:01707-1
SUSE-SU-2025:01919-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:1573-1
SUSE-SU-2025:1574-1
SUSE-SU-2025:20343-1
SUSE-SU-2025:20344-1
SUSE-SU-2025:20354-1
SUSE-SU-2025:20355-1
SUSE-SU-2025_01600-1
SUSE-SU-2025_01614-1
SUSE-SU-2025_01620-1
SUSE-SU-2025_01627-1
SUSE-SU-2025_01633-1
SUSE-SU-2025_01707-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01967-1
USN-7591-1
USN-7591-2
USN-7591-3
USN-7591-4
USN-7591-5
USN-7591-6
USN-7592-1
USN-7593-1
USN-7594-1
USN-7594-2
USN-7594-3
USN-7597-1
USN-7597-2
USN-7598-1
USN-7602-1
USN-7605-1
USN-7605-2
USN-7606-1
USN-7628-1
USN-7655-1
USN-7835-1
USN-7835-2
USN-7835-3
USN-7835-4
USN-7835-5
USN-7835-6
USN-7887-1
USN-7887-2
USN-7940-1
USN-7940-2

Affected Products

Almalinux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu