In the Linux kernel, the following vulnerability has been resolved:
devlink: fix xa_alloc_cyclic() error handling
In case of returning 1 from xa_alloc_cyclic() (wrapping) ERR_PTR(1) will
be returned, which will cause IS_ERR() to be false. Which can lead to
dereference not allocated pointer (rel).
Fix it by checking if err is lower than zero.
This wasn't found in real usecase, only noticed. Credit to Pierre.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-04-08 09:15
Updated : 2025-10-28 17:08
NVD link : CVE-2025-22017
Mitre link : CVE-2025-22017
CVE.ORG link : CVE-2025-22017
JSON object : View
Products Affected
linux
- linux_kernel
CWE
CWE-476
NULL Pointer Dereference
