目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-37805— Linux kernel 安全漏洞

AI 预测 5.5 利用难度: 困难 EPSS 0.17% · P6

可能的 ATT&CK 技术 1AI

T1211 · Exploitation for Stealth

影响版本矩阵 14

厂商产品版本范围状态
LinuxLinux29b96bf50ba958eb5f097cdc3fbd4c1acf9547a2< e03b10c45c7675b6098190c6e7de1b656d8bcdbeaffected
29b96bf50ba958eb5f097cdc3fbd4c1acf9547a2< 54c7b864fbe4423a07b443a4ada0106052942116affected
29b96bf50ba958eb5f097cdc3fbd4c1acf9547a2< 5be9407b41eae20eef9140f5cfbfcbc3d01aaf45affected
29b96bf50ba958eb5f097cdc3fbd4c1acf9547a2< 66046b586c0aaa9332483bcdbd76e3305d6138e9affected
29b96bf50ba958eb5f097cdc3fbd4c1acf9547a2< 9908498ce929a5a052b79bb7942f9ea317312ce4affected
29b96bf50ba958eb5f097cdc3fbd4c1acf9547a2< 3c7df2e27346eb40a0e86230db1ccab195c97cfeaffected
5.13affected
< 5.13unaffected
… +6 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2025-37805 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
sound/virtio: Fix cancel_sync warnings on uninitialized work_structs
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: sound/virtio: Fix cancel_sync warnings on uninitialized work_structs Betty reported hitting the following warning: [ 8.709131][ T221] WARNING: CPU: 2 PID: 221 at kernel/workqueue.c:4182 ... [ 8.713282][ T221] Call trace: [ 8.713365][ T221] __flush_work+0x8d0/0x914 [ 8.713468][ T221] __cancel_work_sync+0xac/0xfc [ 8.713570][ T221] cancel_work_sync+0x24/0x34 [ 8.713667][ T221] virtsnd_remove+0xa8/0xf8 [virtio_snd ab15f34d0dd772f6d11327e08a81d46dc9c36276] [ 8.713868][ T221] virtsnd_probe+0x48c/0x664 [virtio_snd ab15f34d0dd772f6d11327e08a81d46dc9c36276] [ 8.714035][ T221] virtio_dev_probe+0x28c/0x390 [ 8.714139][ T221] really_probe+0x1bc/0x4c8 ... It seems we're hitting the error path in virtsnd_probe(), which triggers a virtsnd_remove() which iterates over the substreams calling cancel_work_sync() on the elapsed_period work_struct. Looking at the code, from earlier in: virtsnd_probe()->virtsnd_build_devs()->virtsnd_pcm_parse_cfg() We set snd->nsubstreams, allocate the snd->substreams, and if we then hit an error on the info allocation or something in virtsnd_ctl_query_info() fails, we will exit without having initialized the elapsed_period work_struct. When that error path unwinds we then call virtsnd_remove() which as long as the substreams array is allocated, will iterate through calling cancel_work_sync() on the uninitialized work struct hitting this warning. Takashi Iwai suggested this fix, which initializes the substreams structure right after allocation, so that if we hit the error paths we avoid trying to cleanup uninitialized data. Note: I have not yet managed to reproduce the issue myself, so this patch has had limited testing. Feedback or thoughts would be appreciated!
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于未初始化工作结构导致取消同步警告。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 29b96bf50ba958eb5f097cdc3fbd4c1acf9547a2 ~ e03b10c45c7675b6098190c6e7de1b656d8bcdbe -
LinuxLinux 5.13 -

二、漏洞 CVE-2025-37805 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-37805 的情报信息

登录查看更多情报信息。

CVE-2025-37805 补丁与修复 (1)

同批安全公告 · Linux · 2025-05-08 · 共 33 条

CVE-2025-37817Linux kernel 安全漏洞
CVE-2025-37833Linux kernel 安全漏洞
CVE-2025-37834Linux kernel 安全漏洞
CVE-2025-37831Linux kernel 安全漏洞
CVE-2025-37830Linux kernel 安全漏洞
CVE-2025-37829Linux kernel 安全漏洞
CVE-2025-37828Linux kernel 安全漏洞
CVE-2025-37826Linux kernel 安全漏洞
CVE-2025-37827Linux kernel 安全漏洞
CVE-2025-37825Linux kernel 安全漏洞
CVE-2025-37823Linux kernel 安全漏洞
CVE-2025-37824Linux kernel 安全漏洞
CVE-2025-37821Linux kernel 安全漏洞
CVE-2025-37822Linux kernel 安全漏洞
CVE-2025-37820Linux kernel 安全漏洞
CVE-2025-37819Linux kernel 安全漏洞
CVE-2025-37800Linux kernel 安全漏洞
CVE-2025-37818Linux kernel 安全漏洞
CVE-2025-37816Linux kernel 安全漏洞
CVE-2025-37815Linux kernel 安全漏洞

显示前 20 条,共 33 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-37805

暂无评论


发表评论