Answer in brief
CVE-2025-22068 records a Unknown severity vulnerability in ublk: make sure ubq->canceling is set when queue is frozen. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=216c8f5ef0f209a3797292c487bdaa6991ab4b92 <7e3497d7dacb5aee69dd9be842b778083cae0e75 || >=216c8f5ef0f209a3797292c487bdaa6991ab4b92 <5491400589e7572c2d2627ed6384302f7672aa1d || >=216c8f5ef0f209a3797292c487bdaa6991ab4b92 <9158359015f0eda00e521e35b7bc7ebce176aebf || >=216c8f5ef0f209a3797292c487bdaa6991ab4b92 <8741d0737921ec1c03cf59aebf4d01400c2b461a | 7e3497d7dacb5aee69dd9be842b778083cae0e75, 5491400589e7572c2d2627ed6384302f7672aa1d, 9158359015f0eda00e521e35b7bc7ebce176aebf, 8741d0737921ec1c03cf59aebf4d01400c2b461a |
| Linux/Linuxgeneric | 6.7 | Not reported |
Published upstream
Apr 16, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ublk: make sure ubq->canceling is set when queue is frozen Now ublk driver depends on `ubq->canceling` for deciding if the request can be dispatched via uring_cmd & io_uring_cmd_complete_in_task(). Once ubq->canceling is set, the uring_cmd can be done via ublk_cancel_cmd() and io_uring_cmd_done(). So set ubq->canceling when queue is frozen, this way makes sure that the flag can be observed from ublk_queue_rq() reliably, and avoids use-after-free on uring_cmd.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-22068 records a Unknown severity vulnerability in ublk: make sure ubq->canceling is set when queue is frozen. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=216c8f5ef0f209a3797292c487bdaa6991ab4b92 <7e3497d7dacb5aee69dd9be842b778083cae0e75 || >=216c8f5ef0f209a3797292c487bdaa6991ab4b92 <5491400589e7572c2d2627ed6384302f7672aa1d || >=216c8f5ef0f209a3797292c487bdaa6991ab4b92 <9158359015f0eda00e521e35b7bc7ebce176aebf || >=216c8f5ef0f209a3797292c487bdaa6991ab4b92 <8741d0737921ec1c03cf59aebf4d01400c2b461a | 7e3497d7dacb5aee69dd9be842b778083cae0e75, 5491400589e7572c2d2627ed6384302f7672aa1d, 9158359015f0eda00e521e35b7bc7ebce176aebf, 8741d0737921ec1c03cf59aebf4d01400c2b461a |
| Linux/Linuxgeneric | 6.7 | Not reported |
Published upstream
Apr 16, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ublk: make sure ubq->canceling is set when queue is frozen Now ublk driver depends on `ubq->canceling` for deciding if the request can be dispatched via uring_cmd & io_uring_cmd_complete_in_task(). Once ubq->canceling is set, the uring_cmd can be done via ublk_cancel_cmd() and io_uring_cmd_done(). So set ubq->canceling when queue is frozen, this way makes sure that the flag can be observed from ublk_queue_rq() reliably, and avoids use-after-free on uring_cmd.
Quoted source text, attributed separately from HOL analysis.