PT-2025-22242 · Linux+3 · Linux Kernel+3

Published

2025-04-03

·

Updated

2025-07-16

·

CVE-2025-37981

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel's smartpqi driver has been identified. The driver incorrectly checks the reset devices variable to determine if special adjustments are needed for kdump, leading to issues such as lower driver parameters like max transfer size after a regular kexec reboot. More critically, kexec reboot tests have shown memory corruption caused by the driver log being written to system memory after a kexec. This issue is resolved by using the is kdump kernel() function instead of reset devices where appropriate.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-11812
CVE-2025-37981
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
USN-7594-1
USN-7594-2
USN-7594-3

Affected Products

Astra Linux
Linux Kernel
Suse
Ubuntu