
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-22063 is a vulnerability discovered in the Linux kernel's netlabel subsystem, specifically related to a NULL pointer exception caused by CALIPSO on IPv4 sockets. The vulnerability was disclosed on April 16, 2025 (NVD).
The vulnerability occurs when calling netlbl_conn_setattr(), where addr->sa_family is used to determine the function behavior. If an IPv4 socket is used but the connect function is called with an IPv6 address, the function calipso_sock_setattr() is triggered. Inside this function, the code executes 'sk_fullsock(__sk) ? inet_sk(__sk)->pinet6 : NULL', which leads to a null pointer dereference since pinet6 is NULL for IPv4 sockets (Debian Tracker).
The vulnerability could lead to a NULL pointer dereference in the Linux kernel, potentially causing system crashes or denial of service conditions (NVD).
The issue has been fixed by implementing a check to verify if inet6_sk(sk) returns a NULL pointer before accessing pinet6. The fix has been incorporated into Linux kernel version 6.12.25-1 and later versions (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."