CVE-2025-22019

Advisory lineage Upstream: 0 Downstream: 19
Analyzed
Published: 16 Apr 2025, 10:20
Last modified:11 May 2026, 21:11

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.03% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Apr 2025, 10:20
Published
Vulnerability first disclosed
11 May 2026, 21:11
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: bcachefs: bch2_ioctl_subvolume_destroy() fixes bch2_evict_subvolume_inodes() was getting stuck - due to incorrectly pruning the dcache. Also, fix missing permissions checks.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.03% Percentile: 9%

Affected Systems

  • linuxlinux

    ≥ 1c6fdbd8f2465ddfb73a01ec620cbf3d14044e1a, < 9e6e83e1e2d01b99e70cd7812d7f758a8def9fc8 | ≥ 1c6fdbd8f2465ddfb73a01ec620cbf3d14044e1a, < 82383abd39abd635511b8956284a5cc8134c4dc1 | ≥ 1c6fdbd8f2465ddfb73a01ec620cbf3d14044e1a, < 558317a5c61045d460a37372181e7b43c0c002bb | ≥ 1c6fdbd8f2465ddfb73a01ec620cbf3d14044e1a, < 707549600c4a012ed71c0204a7992a679880bf33 | 6.7

  • linuxlinux_kernel

    ≥ 6.7, < 6.12.22 | ≥ 6.13, < 6.13.10 | ≥ 6.14, < 6.14.2

References (4)