PT-2025-20362 · Linux+4 · Linux Kernel+4

Published

2025-04-15

·

Updated

2026-05-26

·

CVE-2025-37833

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.11.5
Description A vulnerability in the Linux kernel has been resolved, specifically in the net/niu component. The issue arises when the MSIX ENTRY DATA fields are not touched before entry reads, causing a fatal trap on sparc systems. To work around a bug in the hardware or firmware, the PCI DEV FLAGS MSIX TOUCH ENTRY DATA FIRST flag is set on the struct pci dev. The vulnerability occurs when any registers in a vector entry are read before the ENTRY DATA register is written to, resulting in a non-resumable error. Testing indicates that writing to other registers is not sufficient to prevent the fatal trap. This issue only needs to happen once after power-up, and simply rebooting into a kernel lacking this fix will not cause the trap.
Recommendations For Linux kernel version 6.11.5 and earlier, update to a newer version that includes the fix for this issue. As a temporary workaround, consider disabling the niu try msix() function until a patch is available. Restrict access to the vulnerable msix prepare msi desc() function to minimize the risk of exploitation. Avoid using the ENTRY DATA register in the affected msix table until the issue is resolved.

Exploit

Fix

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2026-02376
CVE-2025-37833
ECHO-7DEA-2697-B98E
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:01972-1
SUSE-SU-2025:01983-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_01972-1
SUSE-SU-2025_01983-1
SUSE-SU-2025_02000-1
USN-7594-1
USN-7594-2
USN-7594-3

Affected Products

Astra Linux
Debian
Linux Kernel
Suse
Ubuntu