CVE-2025-22018 is a Null Pointer Dereference vulnerability in the Linux kernel's ATM subsystem, specifically within the MPOA_cache_impos_rcvd() function. This flaw allows an attacker to trigger a system crash (denial of service) if both 'entry' and 'holding_time' parameters are NULL when the function receives a message. Rated with a CVSS score of 5.5 (Medium), this vulnerability has a local attack vector and low attack complexity, requiring local access and privileges to exploit. The primary impact is a high availability loss, as it can lead to a system crash. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) or significant community discussion has been identified. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.12, < 5.4.292CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.236CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.180CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.133CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.86CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP9 Security Updates
Feb 2, 2026HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025kernel: atm: Fix NULL pointer dereference
Apr 16, 2025atm: Fix NULL pointer dereference
Apr 8, 2025