目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2025-37935— Linux kernel 安全漏洞

CVSS 9.8 · Critical EPSS 0.44% · P36

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 10

ベンダープロダクトVersion Rangeステータス
LinuxLinux2d75891ebc09ba9cf30697dfd54497ef0220308f< cb625f783f70dc6614f03612b8e64ad99cb0a13caffected
2d75891ebc09ba9cf30697dfd54497ef0220308f< 317013d1ad13524be02d60b9e98f08fbd13f8c14affected
2d75891ebc09ba9cf30697dfd54497ef0220308f< 67619cf69dec5d1d7792808dfa548616742dd51daffected
2d75891ebc09ba9cf30697dfd54497ef0220308f< 6e0490fc36cdac696f96e57b61d93b9ae32e0f4caffected
6.6affected
< 6.6unaffected
6.6.90≤ 6.6.*unaffected
6.12.28≤ 6.12.*unaffected
… +2 more rows
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2025-37935の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
net: ethernet: mtk_eth_soc: fix SER panic with 4GB+ RAM
ソース: CVE Program / CVE List V5
脆弱性説明
In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: fix SER panic with 4GB+ RAM If the mtk_poll_rx() function detects the MTK_RESETTING flag, it will jump to release_desc and refill the high word of the SDP on the 4GB RFB. Subsequently, mtk_rx_clean will process an incorrect SDP, leading to a panic. Add patch from MediaTek's SDK to resolve this.
ソース: CVE Program / CVE List V5
CVSS情報
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5
脆弱性タイトル
Linux kernel 安全漏洞
ソース: CNNVD (China National Vulnerability Database)
脆弱性説明
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于mtk_eth_soc在4GB以上RAM时SER崩溃。
ソース: CNNVD (China National Vulnerability Database)
CVSS情報
N/A
ソース: CNNVD (China National Vulnerability Database)
脆弱性タイプ
N/A
ソース: CNNVD (China National Vulnerability Database)

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
LinuxLinux 2d75891ebc09ba9cf30697dfd54497ef0220308f ~ cb625f783f70dc6614f03612b8e64ad99cb0a13c -
LinuxLinux 6.6 -

II. CVE-2025-37935の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2025-37935のインテリジェンス情報

登录查看更多情报信息。

Same Patch Batch · Linux · 2025-05-20 · 95 CVEs total

CVE-2025-378949.8 CRITICALnet: use sock_gen_put() when sk_state is TCP_TIME_WAIT
CVE-2025-379249.8 CRITICALksmbd: fix use-after-free in kerberos authentication
CVE-2025-379599.4 CRITICALbpf: Scrub packet on bpf_redirect_peer
CVE-2025-379188.8 HIGHBluetooth: btusb: avoid NULL pointer dereference in skb_dequeue()
CVE-2025-378998.8 HIGHksmbd: fix use-after-free in session logoff
CVE-2025-379448.8 HIGHwifi: ath12k: Fix invalid entry fetch in ath12k_dp_mon_srng_process
CVE-2025-379268.8 HIGHksmbd: fix use-after-free in ksmbd_session_rpc_open
CVE-2025-379438.8 HIGHwifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi
CVE-2025-379478.8 HIGHksmbd: prevent out-of-bounds stream writes by validating *pos
CVE-2025-379528.8 HIGHksmbd: Fix UAF in __close_file_table_ids
CVE-2025-379568.8 HIGHksmbd: prevent rename with empty string
CVE-2025-379578.8 HIGHKVM: SVM: Forcibly leave SMM mode on SHUTDOWN interception
CVE-2025-379368.7 HIGHperf/x86/intel: KVM: Mask PEBS_ENABLE loaded for guest with vCPU's value.
CVE-2025-379738.1 HIGHwifi: cfg80211: fix out-of-bounds access during multi-link element defragmentation
CVE-2025-379497.8 HIGHxenbus: Use kref to track req lifetime
CVE-2025-379777.8 HIGHscsi: ufs: exynos: Disable iocc if dma-coherent property isn't set
CVE-2025-379207.8 HIGHxsk: Fix race condition in AF_XDP generic RX path
CVE-2025-379217.8 HIGHvxlan: vnifilter: Fix unlocked deletion of default FDB entry
CVE-2025-379037.8 HIGHdrm/amd/display: Fix slab-use-after-free in hdcp
CVE-2025-379017.8 HIGHirqchip/qcom-mpm: Prevent crash when trying to handle non-wake GPIOs

Showing 20 of 95 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2025-37935へのコメント

まだコメントはありません


コメントを残す