PT-2025-21912 · Linux+5 · Linux Kernel+5

Published

2025-05-19

·

Updated

2026-04-20

·

CVE-2025-37891

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.6.93
Description The Linux kernel contains a buffer overflow in the ALSA subsystem, specifically within the UMP (Unified MIDI Packet) SysEx message conversion process. The do convert to ump() function uses an internal buffer of size 4 to store incoming MIDI bytes, assuming a maximum size of 4 for MIDI1 UMP packet data. However, SysEx messages can be up to 6 bytes long, leading to a buffer overflow when processing these messages. This can potentially corrupt memory. The fix involves increasing the buffer size to 6 to accommodate SysEx messages. This vulnerability was discovered by an AI-powered vulnerability hunter named Argusee and may enable Local Privilege Escalation (LPE).
Recommendations Upgrade to Linux kernel version 6.6.93 or later.

Exploit

Fix

LPE

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-10601
CVE-2025-37891
MGASA-2025-0182
MGASA-2025-0183
OESA-2025-2767
RHSA-2026:0804
RHSA-2026:0917
RHSA-2026:1236
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_02000-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
USN-7649-1
USN-7649-2
USN-7650-1
USN-7665-1
USN-7665-2
USN-7721-1
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Affected Products

Astra Linux
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu