目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-22045— Linux kernel 安全漏洞

CVSS 7.8 · High EPSS 0.21% · P11

影响版本矩阵 20

厂商产品版本范围状态
LinuxLinux016c4d92cd16f569c6485ae62b076c1a4b779536< 618d5612ecb7bfc1c85342daafeb2b47e29e77a3affected
016c4d92cd16f569c6485ae62b076c1a4b779536< 556d446068f90981e5d71ca686bdaccdd545d491affected
016c4d92cd16f569c6485ae62b076c1a4b779536< 0a8f806ea6b5dd64b3d1f05ff774817d5f7ddbd1affected
016c4d92cd16f569c6485ae62b076c1a4b779536< 0708fd6bd8161871bfbadced2ca4319b84ab44feaffected
016c4d92cd16f569c6485ae62b076c1a4b779536< 7085895c59e4057ffae17f58990ccb630087d0d2affected
016c4d92cd16f569c6485ae62b076c1a4b779536< 93224deb50a8d20df3884f3672ce9f982129aa50affected
016c4d92cd16f569c6485ae62b076c1a4b779536< 320ac1af4c0bdb92c864dc9250d1329234820edfaffected
016c4d92cd16f569c6485ae62b076c1a4b779536< 78d6f9a9eb2a5da6fcbd76d6191d24b0dcc321beaffected
… +12 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2025-22045 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: x86/mm: Fix flush_tlb_range() when used for zapping normal PMDs On the following path, flush_tlb_range() can be used for zapping normal PMD entries (PMD entries that point to page tables) together with the PTE entries in the pointed-to page table: collapse_pte_mapped_thp pmdp_collapse_flush flush_tlb_range The arm64 version of flush_tlb_range() has a comment describing that it can be used for page table removal, and does not use any last-level invalidation optimizations. Fix the X86 version by making it behave the same way. Currently, X86 only uses this information for the following two purposes, which I think means the issue doesn't have much impact: - In native_flush_tlb_multi() for checking if lazy TLB CPUs need to be IPI'd to avoid issues with speculative page table walks. - In Hyper-V TLB paravirtualization, again for lazy TLB stuff. The patch "x86/mm: only invalidate final translations with INVLPGB" which is currently under review (see <https://lore.kernel.org/all/20241230175550.4046587-13-riel@surriel.com/>) would probably be making the impact of this a lot worse.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于flush_tlb_range在清除普通PMD条目时行为不当。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 016c4d92cd16f569c6485ae62b076c1a4b779536 ~ 618d5612ecb7bfc1c85342daafeb2b47e29e77a3 -
LinuxLinux 4.20 -

二、漏洞 CVE-2025-22045 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-22045 的情报信息

登录查看更多情报信息。

CVE-2025-22045 补丁与修复 (1)

CVE-2025-22045 其他参考 (8)

同批安全公告 · Linux · 2025-04-16 · 共 127 条

CVE-2025-2202110.0 CRITICALLinux kernel 安全漏洞
CVE-2025-221109.8 CRITICALLinux kernel 安全漏洞
CVE-2025-220779.8 CRITICALLinux kernel 安全漏洞
CVE-2025-220889.8 CRITICALLinux kernel 安全漏洞
CVE-2025-220748.8 HIGHLinux kernel 安全漏洞
CVE-2025-231338.8 HIGHLinux kernel 安全漏洞
CVE-2025-221188.8 HIGHLinux kernel 安全漏洞
CVE-2025-220868.8 HIGHLinux kernel 安全漏洞
CVE-2025-220408.8 HIGHLinux kernel 安全漏洞
CVE-2025-220418.8 HIGHLinux kernel 安全漏洞
CVE-2025-220398.8 HIGHLinux kernel 安全漏洞
CVE-2024-580968.8 HIGHLinux kernel 安全漏洞
CVE-2025-221178.7 HIGHLinux kernel 安全漏洞
CVE-2025-221088.6 HIGHLinux kernel 安全漏洞
CVE-2025-221218.4 HIGHLinux kernel 安全漏洞
CVE-2025-220808.4 HIGHLinux kernel 安全漏洞
CVE-2025-220388.3 HIGHLinux kernel 安全漏洞
CVE-2025-220438.1 HIGHLinux kernel 安全漏洞
CVE-2025-220428.1 HIGHLinux kernel 安全漏洞
CVE-2025-220497.8 HIGHLinux kernel 安全漏洞

显示前 20 条,共 127 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-22045

暂无评论


发表评论