PT-2025-20534 · Linux+3 · Linux Kernel+3

Published

2025-03-06

·

Updated

2026-05-26

·

CVE-2025-37882

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue concerns the handling of isochronous Ring Underrun/Overrun events in the Linux kernel's xHCI (Extensible Host Controller Interface) implementation. Specifically, when such an event occurs, the TRB (Transfer Ring Buffer) pointer may point to a different location than expected, potentially leading to data loss or buffer use-after-free (UAF) issues. This can happen due to a race condition where a new TD (Transfer Descriptor) is queued at the same ring position before the event is handled. The problem is exacerbated by interrupt moderation delays or system load, which can increase the likelihood of this race condition occurring.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-62753
AZL-70159
BDU:2026-02236
CVE-2025-37882
ECHO-40C9-3483-4FBA
RHSA-2026:2759
RHSA-2026:2766
RHSA-2026:3267
RHSA-2026:3358
RHSA-2026:3579
RHSA-2026:4244
RHSA-2026:4245
USN-7594-1
USN-7594-2
USN-7594-3

Affected Products

Astra Linux
Debian
Linux Kernel
Ubuntu