PT-2025-18471 · Linux+3 · Linux Kernel+3

Publicado

2025-04-09

·

Atualizado

2025-07-16

·

CVE-2025-37791

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.11.0
Description A vulnerability in the Linux kernel has been resolved, related to the ethtool cmis cdb module. The issue arises from using the incorrect size of the rpl pointer in the ethtool cmis module poll() function, which can cause stack corruption. This corruption can lead to a kernel panic, as indicated by a stack-protector error message. The vulnerability is associated with the ethtool cmis wait for cond() function and can be triggered during the execution of ethtool cmis cdb execute cmd() and other related functions.
Recommendations For Linux kernel versions prior to 6.11.0, update to version 6.11.0 or later to resolve the issue. As a temporary workaround, consider disabling the ethtool cmis module poll() function until a patch is available. Restrict access to the ethtool module to minimize the risk of exploitation. Avoid using the rpl pointer in the affected API endpoints until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-12310
CVE-2025-37791
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
USN-7594-1
USN-7594-2
USN-7594-3

Produtos afetados

Astra Linux
Linux Kernel
Suse
Ubuntu