Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-21822— ptp: vmclock: Set driver data before its usage

AI Predicted 3.3 Difficulty: Trivial EPSS 0.17% · P7

Affected Version Matrix 6

VendorProductVersion RangeStatus
LinuxLinux20503272422693d793b84f88bf23fe4e955d3a33< 6dbd8b91a065d1d8001446a28e72cd140f9acef0affected
20503272422693d793b84f88bf23fe4e955d3a33< f7d07cd4f77d77f366c8ffbb8ba8b61f614e5fceaffected
6.13affected
< 6.13unaffected
6.13.4≤ 6.13.*unaffected
6.14≤ *unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-21822

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ptp: vmclock: Set driver data before its usage
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ptp: vmclock: Set driver data before its usage If vmclock_ptp_register() fails during probing, vmclock_remove() is called to clean up the ptp clock and misc device. It uses dev_get_drvdata() to access the vmclock state. However the driver data is not yet set at this point. Assign the driver data earlier.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于vmclock_ptp_register失败时未设置驱动数据,导致清理时访问未初始化数据。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 20503272422693d793b84f88bf23fe4e955d3a33 ~ 6dbd8b91a065d1d8001446a28e72cd140f9acef0 -
LinuxLinux 6.13 -

II. Public POCs for CVE-2025-21822

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-21822

登录查看更多情报信息。

Patches & Fixes for CVE-2025-21822 (2)

Same Patch Batch · Linux · 2025-02-27 · 177 CVEs total

CVE-2025-218059.8 CRITICALRDMA/rtrs: Add missing deinit() call
CVE-2025-217969.8 CRITICALnfsd: clear acl_access/acl_default after releasing them
CVE-2025-217079.8 CRITICALmptcp: consolidate suboption status
CVE-2025-217489.8 CRITICALksmbd: fix integer overflows on 32 bit systems
CVE-2024-580069.6 CRITICALPCI: dwc: ep: Prevent changing BAR size/flags in pci_epc_set_bar()
CVE-2024-579998.8 HIGHpowerpc/pseries/iommu: IOMMU incorrectly marks MMIO range in DDW
CVE-2025-217358.8 HIGHNFC: nci: Add bounds checking in nci_hci_create_pipe()
CVE-2024-579978.8 HIGHwifi: wcn36xx: fix channel survey memory allocation size
CVE-2024-579958.8 HIGHwifi: ath12k: fix read pointer after free in ath12k_mac_assign_vif_to_vdev()
CVE-2025-217108.2 HIGHtcp: correct handling of extreme memory squeeze
CVE-2025-217668.1 HIGHipv4: use RCU protection in __ip_rt_update_pmtu()
CVE-2024-579738.1 HIGHrdma/cxgb4: Prevent potential integer overflow on 32bit
CVE-2025-217658.1 HIGHipv6: use RCU protection in ip6_default_advmss()
CVE-2025-217608.1 HIGHndisc: extend RCU protection in ndisc_send_skb()
CVE-2025-217628.1 HIGHarp: use RCU protection in arp_xmit()
CVE-2024-580107.8 HIGHbinfmt_flat: Fix integer overflow bug on 32 bit systems
CVE-2024-580087.8 HIGHKEYS: trusted: dcp: fix improper sg use with CONFIG_VMAP_STACK=y
CVE-2025-217647.8 HIGHndisc: use RCU protection in ndisc_alloc_skb()
CVE-2025-217917.8 HIGHvrf: use RCU protection in l3mdev_l3_out()
CVE-2025-217637.8 HIGHneighbour: use RCU protection in __neigh_notify()

Showing top 20 of 177 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-21822

No comments yet


Leave a comment