目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-37833— Linux kernel 安全漏洞

AI 预测 5.3 利用难度: 困难 EPSS 0.16% · P6

可能的 ATT&CK 技术 1AI

T1498 · Network Denial of Service

影响版本矩阵 22

厂商产品版本范围状态
LinuxLinux7d5ec3d3612396dc6d4b76366d20ab9fc06f399f< c187aaa9e79b4b6d86ac7ba941e579ad33df5538affected
7d5ec3d3612396dc6d4b76366d20ab9fc06f399f< 64903e4849a71cf7f7c7e5d45225ccefc1280929affected
7d5ec3d3612396dc6d4b76366d20ab9fc06f399f< fbb429ddff5c8e479edcc7dde5a542c9295944e6affected
e6454fd429b0ba6513ac1de27a0bd6ccac021a40affected
3590d16b47ac561a4f2504befe43def10ed1814caffected
e1d5e8a561baaafed6e35d72a6ad53d248580d6caffected
3b570884c868c12e3184627ce4b4a167e9d6f018affected
1866c8f6d43c3c6ffa2bfe086b65392b3a3fafb1affected
… +14 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2025-37833 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
net/niu: Niu requires MSIX ENTRY_DATA fields touch before entry reads
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: net/niu: Niu requires MSIX ENTRY_DATA fields touch before entry reads Fix niu_try_msix() to not cause a fatal trap on sparc systems. Set PCI_DEV_FLAGS_MSIX_TOUCH_ENTRY_DATA_FIRST on the struct pci_dev to work around a bug in the hardware or firmware. For each vector entry in the msix table, niu chips will cause a fatal trap if any registers in that entry are read before that entries' ENTRY_DATA register is written to. Testing indicates writes to other registers are not sufficient to prevent the fatal trap, however the value does not appear to matter. This only needs to happen once after power up, so simply rebooting into a kernel lacking this fix will NOT cause the trap. NON-RESUMABLE ERROR: Reporting on cpu 64 NON-RESUMABLE ERROR: TPC [0x00000000005f6900] <msix_prepare_msi_desc+0x90/0xa0> NON-RESUMABLE ERROR: RAW [4010000000000016:00000e37f93e32ff:0000000202000080:ffffffffffffffff NON-RESUMABLE ERROR: 0000000800000000:0000000000000000:0000000000000000:0000000000000000] NON-RESUMABLE ERROR: handle [0x4010000000000016] stick [0x00000e37f93e32ff] NON-RESUMABLE ERROR: type [precise nonresumable] NON-RESUMABLE ERROR: attrs [0x02000080] < ASI sp-faulted priv > NON-RESUMABLE ERROR: raddr [0xffffffffffffffff] NON-RESUMABLE ERROR: insn effective address [0x000000c50020000c] NON-RESUMABLE ERROR: size [0x8] NON-RESUMABLE ERROR: asi [0x00] CPU: 64 UID: 0 PID: 745 Comm: kworker/64:1 Not tainted 6.11.5 #63 Workqueue: events work_for_cpu_fn TSTATE: 0000000011001602 TPC: 00000000005f6900 TNPC: 00000000005f6904 Y: 00000000 Not tainted TPC: <msix_prepare_msi_desc+0x90/0xa0> g0: 00000000000002e9 g1: 000000000000000c g2: 000000c50020000c g3: 0000000000000100 g4: ffff8000470307c0 g5: ffff800fec5be000 g6: ffff800047a08000 g7: 0000000000000000 o0: ffff800014feb000 o1: ffff800047a0b620 o2: 0000000000000011 o3: ffff800047a0b620 o4: 0000000000000080 o5: 0000000000000011 sp: ffff800047a0ad51 ret_pc: 00000000005f7128 RPC: <__pci_enable_msix_range+0x3cc/0x460> l0: 000000000000000d l1: 000000000000c01f l2: ffff800014feb0a8 l3: 0000000000000020 l4: 000000000000c000 l5: 0000000000000001 l6: 0000000020000000 l7: ffff800047a0b734 i0: ffff800014feb000 i1: ffff800047a0b730 i2: 0000000000000001 i3: 000000000000000d i4: 0000000000000000 i5: 0000000000000000 i6: ffff800047a0ae81 i7: 00000000101888b0 I7: <niu_try_msix.constprop.0+0xc0/0x130 [niu]> Call Trace: [<00000000101888b0>] niu_try_msix.constprop.0+0xc0/0x130 [niu] [<000000001018f840>] niu_get_invariants+0x183c/0x207c [niu] [<00000000101902fc>] niu_pci_init_one+0x27c/0x2fc [niu] [<00000000005ef3e4>] local_pci_probe+0x28/0x74 [<0000000000469240>] work_for_cpu_fn+0x8/0x1c [<000000000046b008>] process_scheduled_works+0x144/0x210 [<000000000046b518>] worker_thread+0x13c/0x1c0 [<00000000004710e0>] kthread+0xb8/0xc8 [<00000000004060c8>] ret_from_fork+0x1c/0x2c [<0000000000000000>] 0x0 Kernel panic - not syncing: Non-resumable error.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于硬件缺陷,可能导致致命错误。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux 7d5ec3d3612396dc6d4b76366d20ab9fc06f399f ~ c187aaa9e79b4b6d86ac7ba941e579ad33df5538 -
LinuxLinux 5.14 -

二、漏洞 CVE-2025-37833 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-37833 的情报信息

登录查看更多情报信息。

同批安全公告 · Linux · 2025-05-08 · 共 33 条

CVE-2025-378017.8 HIGHLinux kernel 安全漏洞
CVE-2025-378227.8 HIGHLinux kernel 安全漏洞
CVE-2025-378147.8 HIGHLinux kernel 安全漏洞
CVE-2025-378137.8 HIGHLinux kernel 安全漏洞
CVE-2025-378237.8 HIGHLinux kernel 安全漏洞
CVE-2025-378207.5 HIGHLinux kernel 安全漏洞
CVE-2025-378027.5 HIGHLinux kernel 安全漏洞
CVE-2025-378007.1 HIGHLinux kernel 安全漏洞
CVE-2025-37829Linux kernel 安全漏洞
CVE-2025-37828Linux kernel 安全漏洞
CVE-2025-37826Linux kernel 安全漏洞
CVE-2025-37827Linux kernel 安全漏洞
CVE-2025-37825Linux kernel 安全漏洞
CVE-2025-37830Linux kernel 安全漏洞
CVE-2025-37831Linux kernel 安全漏洞
CVE-2025-37824Linux kernel 安全漏洞
CVE-2025-37821Linux kernel 安全漏洞
CVE-2025-37834Linux kernel 安全漏洞
CVE-2025-37819Linux kernel 安全漏洞
CVE-2025-37817Linux kernel 安全漏洞

显示前 20 条,共 33 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-37833

暂无评论


发表评论