CVE-2025-22109: ax25: Remove broken autobind
ax25: Remove broken autobind
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
ax25-tools and ax25-apps packages for ax25from your environment.Remove the broken autobind feature from the ax25-tools and ax25-apps packages for AF_AX25 ("ax25: Remove broken autobind").
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22109?
CVE-2025-22109 is classified as a medium severity vulnerability due to memory leaks associated with the ax25 socket autobind feature.
How do I fix CVE-2025-22109?
To fix CVE-2025-22109, update the Linux kernel to version 6.14.0-rc5 or later, where the issue has been resolved.
What are the potential impacts of CVE-2025-22109?
The potential impacts of CVE-2025-22109 include memory leaks affecting system performance and stability when using the ax25 socket autobind feature.
Which versions of the Linux kernel are affected by CVE-2025-22109?
CVE-2025-22109 affects the Linux kernel version 6.14.0-rc4 and possibly earlier versions.
Is CVE-2025-22109 simple to exploit?
CVE-2025-22109 may not be simple to exploit as it requires knowledge of the ax25 socket implementation and specific conditions to trigger the memory leak.