PT-2025-18453 · Linux+5 · Linux Kernel+5

Published

2025-04-09

·

Updated

2026-04-20

·

CVE-2025-37772

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to the fixed version
Description A vulnerability in the Linux kernel has been resolved, related to the RDMA/cma component. The issue occurs when multiple calls to cma netevent callback() are made in quick succession, causing the overwrite of previously queued work items for the same rdma cm id. This can lead to a kernel crash. The problem is due to the reuse of the struct work struct net work member in struct rdma cm id for enqueuing cma netevent work handler()s onto cma wq. Analysis using drgn indicates that the work item was likely overwritten.
Recommendations To resolve the issue, update the Linux kernel to a version where the fix for the RDMA/cma workqueue crash in cma netevent work handler has been applied. Specifically, the fix involves moving the INIT WORK() to rdma create id(), ensuring that it does not race with any existing queue work() or its worker thread. As a temporary workaround, consider disabling the cma netevent work handler() function until a patch is available.

Exploit

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2025-12158
CVE-2025-37772
DLA-4193-1
ECHO-EB57-625D-DB1F
OESA-2025-2120
OESA-2025-2121
OESA-2025-2122
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_02000-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
USN-7594-1
USN-7594-2
USN-7594-3
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu