目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2025-37927— Linux kernel 安全漏洞

AI 预测 7.8 利用难度: 中等 EPSS 0.21% · P11

影响版本矩阵 18

厂商产品版本范围状态
LinuxLinuxca3bf5d47cec8b7614bcb2e9132c40081d6d81db< 2b65060c84ee4d8dc64fae6d2728b528e9e832e1affected
ca3bf5d47cec8b7614bcb2e9132c40081d6d81db< a65ebfed65fa62797ec1f5f1dcf7adb157a2de1eaffected
ca3bf5d47cec8b7614bcb2e9132c40081d6d81db< 466d9da267079a8d3b69fa72dfa3a732e1f6dbb5affected
ca3bf5d47cec8b7614bcb2e9132c40081d6d81db< c3f37faa71f5d26dd2144b3f2b14525ec8f5e41faffected
ca3bf5d47cec8b7614bcb2e9132c40081d6d81db< 13d67528e1ae4486e9ab24b70122fab104c73c29affected
ca3bf5d47cec8b7614bcb2e9132c40081d6d81db< 10d901a95f8e766e5aa0bb9a983fb41271f64718affected
ca3bf5d47cec8b7614bcb2e9132c40081d6d81db< c8bdfc0297965bb13fa439d36ca9c4f7c8447f0faffected
ca3bf5d47cec8b7614bcb2e9132c40081d6d81db< 8dee308e4c01dea48fc104d37f92d5b58c50b96caffected
… +10 条更多
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2025-37927 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
iommu/amd: Fix potential buffer overflow in parse_ivrs_acpihid
来源: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Fix potential buffer overflow in parse_ivrs_acpihid There is a string parsing logic error which can lead to an overflow of hid or uid buffers. Comparing ACPIID_LEN against a total string length doesn't take into account the lengths of individual hid and uid buffers so the check is insufficient in some cases. For example if the length of hid string is 4 and the length of the uid string is 260, the length of str will be equal to ACPIID_LEN + 1 but uid string will overflow uid buffer which size is 256. The same applies to the hid string with length 13 and uid string with length 250. Check the length of hid and uid strings separately to prevent buffer overflow. Found by Linux Verification Center (linuxtesting.org) with SVACE.
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
N/A
来源: CVE Program / CVE List V5
Vulnerability Title
Linux kernel 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于iommu/amd中parse_ivrs_acpihid函数存在缓冲区溢出风险。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
LinuxLinux ca3bf5d47cec8b7614bcb2e9132c40081d6d81db ~ 2b65060c84ee4d8dc64fae6d2728b528e9e832e1 -
LinuxLinux 4.7 -

二、漏洞 CVE-2025-37927 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2025-37927 的情报信息

登录查看更多情报信息。

CVE-2025-37927 补丁与修复 (1)

同批安全公告 · Linux · 2025-05-20 · 共 95 条

CVE-2025-379249.8 CRITICALLinux kernel 安全漏洞
CVE-2025-37958Linux kernel 安全漏洞
CVE-2025-37954Linux kernel 安全漏洞
CVE-2025-37953Linux kernel 安全漏洞
CVE-2025-37949Linux kernel 安全漏洞
CVE-2025-37948Linux kernel 安全漏洞
CVE-2025-37947Linux kernel 安全漏洞
CVE-2025-37946Linux kernel 安全漏洞
CVE-2025-37945Linux kernel 安全漏洞
CVE-2025-37950Linux kernel 安全漏洞
CVE-2025-37957Linux kernel 安全漏洞
CVE-2025-37956Linux kernel 安全漏洞
CVE-2025-37960Linux kernel 安全漏洞
CVE-2025-37959Linux kernel 安全漏洞
CVE-2025-37961Linux kernel 安全漏洞
CVE-2025-37963Linux kernel 安全漏洞
CVE-2025-37962Linux kernel 安全漏洞
CVE-2025-37964Linux kernel 安全漏洞
CVE-2025-37965Linux kernel 安全漏洞
CVE-2025-37967Linux kernel 安全漏洞

显示前 20 条,共 95 条。 查看全部 &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2025-37927

暂无评论


发表评论