PT-2025-22242 · Linux+3 · Linux Kernel+3

Publicado

2025-04-03

·

Atualizado

2025-07-16

·

CVE-2025-37981

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel's smartpqi driver has been identified. The driver incorrectly checks the reset devices variable to determine if special adjustments are needed for kdump, leading to issues such as lower driver parameters like max transfer size after a regular kexec reboot. More critically, kexec reboot tests have shown memory corruption caused by the driver log being written to system memory after a kexec. This issue is resolved by using the is kdump kernel() function instead of reset devices where appropriate.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-11812
CVE-2025-37981
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
USN-7594-1
USN-7594-2
USN-7594-3

Produtos afetados

Astra Linux
Linux Kernel
Suse
Ubuntu