PT-2025-18428 · Linux+4 · Linux Kernel+4

Published

2025-04-08

·

Updated

2026-05-26

·

CVE-2025-37747

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A hang can occur while freeing a sigtrap event in the Linux kernel's perf subsystem if a related deferred signal hadn't been sent before the file got closed. This issue arises due to a problem with task work and reference counting. The hang occurs because task work cancel() fails, leading to a wait on rcuwait wait event(). The issue is complex and involves inverted dependencies when remote targets are involved.
Recommendations To resolve this issue, acquire the event reference count upon queueing the perf task work and release it from the task work. Adjustments are necessary to make this work, including ensuring that a child event does not dereference its parent upon freeing and that places assuming the event doesn't have any reference held must instead put the reference and let the reference counting do its job. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

AZL-69674
AZL-69680
BDU:2026-06015
CVE-2025-37747
ECHO-9AA4-C7EE-1CA4
OESA-2025-1594
OESA-2025-1595
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:01972-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_01972-1
SUSE-SU-2025_02000-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
USN-7594-1
USN-7594-2
USN-7594-3

Affected Products

Astra Linux
Debian
Linux Kernel
Suse
Ubuntu