CVE-2025-22125

Modified
Published: 16 Apr 2025, 14:13
Last modified:11 May 2026, 21:13

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.03% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Apr 2025, 14:13
Published
Vulnerability first disclosed
11 May 2026, 21:13
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: md/raid1,raid10: don't ignore IO flags If blk-wbt is enabled by default, it's found that raid write performance is quite bad because all IO are throttled by wbt of underlying disks, due to flag REQ_IDLE is ignored. And turns out this behaviour exist since blk-wbt is introduced. Other than REQ_IDLE, other flags should not be ignored as well, for example REQ_META can be set for filesystems, clearing it can cause priority reverse problems; And REQ_NOWAIT should not be cleared as well, because io will wait instead of failing directly in underlying disks. Fix those problems by keep IO flags from master bio. Fises: f51d46d0e7cb ("md: add support for REQ_NOWAIT")

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.03% Percentile: 8%

Affected Systems

  • linuxlinux

    ≥ 5404bc7a87b9949cf61e0174b21f80e73239ab25, < 10f4ff4baeb6951cf58282954318827b6852d501 | ≥ 5404bc7a87b9949cf61e0174b21f80e73239ab25, < 73506e581c0b1814cdfd2229d589f30751d7de26 | ≥ 5404bc7a87b9949cf61e0174b21f80e73239ab25, < 8a0adf3d778c4a0893c6d34a9e1b0082a6f1c495 | ≥ 5404bc7a87b9949cf61e0174b21f80e73239ab25, < e879a0d9cb086c8e52ce6c04e5bfa63825a6213c | 2.6.19

  • linuxlinux_kernel

    ≥ 2.6.19, < 6.12.46 | ≥ 6.13, < 6.14.2

References (4)