Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-22125— md/raid1,raid10: don't ignore IO flags

AI Predicted 5.5 Difficulty: Trivial EPSS 0.18% · P7

Affected Version Matrix 10

VendorProductVersion RangeStatus
LinuxLinux5404bc7a87b9949cf61e0174b21f80e73239ab25< 10f4ff4baeb6951cf58282954318827b6852d501affected
5404bc7a87b9949cf61e0174b21f80e73239ab25< 73506e581c0b1814cdfd2229d589f30751d7de26affected
5404bc7a87b9949cf61e0174b21f80e73239ab25< 8a0adf3d778c4a0893c6d34a9e1b0082a6f1c495affected
5404bc7a87b9949cf61e0174b21f80e73239ab25< e879a0d9cb086c8e52ce6c04e5bfa63825a6213caffected
2.6.19affected
< 2.6.19unaffected
6.6.136≤ 6.6.*unaffected
6.12.46≤ 6.12.*unaffected
… +2 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-22125

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
md/raid1,raid10: don't ignore IO flags
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: md/raid1,raid10: don't ignore IO flags If blk-wbt is enabled by default, it's found that raid write performance is quite bad because all IO are throttled by wbt of underlying disks, due to flag REQ_IDLE is ignored. And turns out this behaviour exist since blk-wbt is introduced. Other than REQ_IDLE, other flags should not be ignored as well, for example REQ_META can be set for filesystems, clearing it can cause priority reverse problems; And REQ_NOWAIT should not be cleared as well, because io will wait instead of failing directly in underlying disks. Fix those problems by keep IO flags from master bio. Fises: f51d46d0e7cb ("md: add support for REQ_NOWAIT")
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于raid1和raid10忽略IO标志,可能导致性能问题或优先级反转。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 5404bc7a87b9949cf61e0174b21f80e73239ab25 ~ 10f4ff4baeb6951cf58282954318827b6852d501 -
LinuxLinux 2.6.19 -

II. Public POCs for CVE-2025-22125

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-22125

登录查看更多情报信息。

Patches & Fixes for CVE-2025-22125 (1)

Other References for CVE-2025-22125 (1)

Same Patch Batch · Linux · 2025-04-16 · 127 CVEs total

CVE-2025-2202110.0 CRITICALnetfilter: socket: Lookup orig tuple for IPv6 SNAT
CVE-2025-221109.8 CRITICALnetfilter: nfnetlink_queue: Initialize ctx to avoid memory allocation error
CVE-2025-220779.8 CRITICALRevert "smb: client: fix TCP timers deadlock after rmmod"
CVE-2025-220889.8 CRITICALRDMA/erdma: Prevent use-after-free in erdma_accept_newconn()
CVE-2025-220748.8 HIGHksmbd: fix r_count dec/increment mismatch
CVE-2025-221188.8 HIGHice: validate queue quanta parameters to prevent OOB access
CVE-2025-231338.8 HIGHwifi: ath11k: update channel list in reg notifier instead reg worker
CVE-2025-220408.8 HIGHksmbd: fix session use-after-free in multichannel connection
CVE-2025-220418.8 HIGHksmbd: fix use-after-free in ksmbd_sessions_deregister()
CVE-2025-220398.8 HIGHksmbd: fix overflow in dacloffset bounds check
CVE-2025-220868.8 HIGHRDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow
CVE-2025-221178.7 HIGHice: fix using untrusted value of pkt_len in ice_vc_fdir_parse_raw()
CVE-2025-221088.6 HIGHbnxt_en: Mask the bd_cnt field in the TX BD properly
CVE-2025-220808.4 HIGHfs/ntfs3: Prevent integer overflow in hdr_first_de()
CVE-2025-221218.4 HIGHext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all()
CVE-2025-220388.3 HIGHksmbd: validate zero num_subauth before sub_auth is accessed
CVE-2025-220438.1 HIGHksmbd: add bounds check for durable handle context
CVE-2025-220428.1 HIGHksmbd: add bounds check for create lease context
CVE-2025-220687.8 HIGHublk: make sure ubq->canceling is set when queue is frozen
CVE-2025-220817.8 HIGHfs/ntfs3: Fix a couple integer overflows on 32bit systems

Showing top 20 of 127 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-22125

No comments yet


Leave a comment