PT-2025-18471 · Linux+3 · Linux Kernel+3

Published

2025-04-09

·

Updated

2025-07-16

·

CVE-2025-37791

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.11.0
Description A vulnerability in the Linux kernel has been resolved, related to the ethtool cmis cdb module. The issue arises from using the incorrect size of the rpl pointer in the ethtool cmis module poll() function, which can cause stack corruption. This corruption can lead to a kernel panic, as indicated by a stack-protector error message. The vulnerability is associated with the ethtool cmis wait for cond() function and can be triggered during the execution of ethtool cmis cdb execute cmd() and other related functions.
Recommendations For Linux kernel versions prior to 6.11.0, update to version 6.11.0 or later to resolve the issue. As a temporary workaround, consider disabling the ethtool cmis module poll() function until a patch is available. Restrict access to the ethtool module to minimize the risk of exploitation. Avoid using the rpl pointer in the affected API endpoints until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12310
CVE-2025-37791
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
USN-7594-1
USN-7594-2
USN-7594-3

Affected Products

Astra Linux
Linux Kernel
Suse
Ubuntu