cbcvebase.
CVE-2025-37756
published 2025-05-01

CVE-2025-37756: In the Linux kernel, the following vulnerability has been resolved: net: tls: explicitly disallow disconnect syzbot discovered that it can disconnect a TLS…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.31%
23.8th percentile
In the Linux kernel, the following vulnerability has been resolved: net: tls: explicitly disallow disconnect syzbot discovered that it can disconnect a TLS socket and then run into all sort of unexpected corner cases. I have a vague recollection of Eric pointing this out to us a long time ago. Supporting disconnect is really hard, for one thing if offload is enabled we'd need to wait for all packets to be _acked_. Disconnect is not commonly used, disallow it. The immediate problem syzbot run into is the warning in the strp, but that's just the easiest bug to trigger: WARNING: CPU: 0 PID: 5834 at net/tls/tls_strp.c:486 tls_strp_msg_load+0x72e/0xa80 net/tls/tls_strp.c:486 RIP: 0010:tls_strp_msg_load+0x72e/0xa80 net/tls/tls_strp.c:486 Call Trace: tls_rx_rec_wait+0x280/0xa60 net/tls/tls_sw.c:1363 tls_sw_recvmsg+0x85c/0x1c30 net/tls/tls_sw.c:2043 inet6_recvmsg+0x2c9/0x730 net/ipv6/af_inet6.c:678 sock_recvmsg_nosec net/socket.c:1023 [inline] sock_recvmsg+0x109/0x280 net/socket.c:1045 __sys_recvfrom+0x202/0x380 net/socket.c:2237

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
googlechrome_chrome
linuxlinux
linuxlinux>= 3c4d7559159bfe1e3b94df3a657b2cda3a34e218 < 7bdcf5bc35ae59fc4a0fa23276e84b4d1534a3cf7bdcf5bc35ae59fc4a0fa23276e84b4d1534a3cf
linuxlinux>= 3c4d7559159bfe1e3b94df3a657b2cda3a34e218 < ac91c6125468be720eafde9c973994cb45b61d44ac91c6125468be720eafde9c973994cb45b61d44
linuxlinux>= 3c4d7559159bfe1e3b94df3a657b2cda3a34e218 < f3ce4d3f874ab7919edca364c147ac735f9f1d04f3ce4d3f874ab7919edca364c147ac735f9f1d04
linuxlinux>= 3c4d7559159bfe1e3b94df3a657b2cda3a34e218 < 2bcad8fefcecdd5f005d8c550b25d703c063c34a2bcad8fefcecdd5f005d8c550b25d703c063c34a
linuxlinux>= 3c4d7559159bfe1e3b94df3a657b2cda3a34e218 < 9fcbca0f801580cbb583e9cb274e2c7fbe766ca69fcbca0f801580cbb583e9cb274e2c7fbe766ca6
linuxlinux>= 3c4d7559159bfe1e3b94df3a657b2cda3a34e218 < c665bef891e8972e1d3ce5bbc0d42a373346a2c3c665bef891e8972e1d3ce5bbc0d42a373346a2c3
linuxlinux>= 3c4d7559159bfe1e3b94df3a657b2cda3a34e218 < 8513411ec321942bd3cfed53d5bb700665c67d868513411ec321942bd3cfed53d5bb700665c67d86
linuxlinux>= 3c4d7559159bfe1e3b94df3a657b2cda3a34e218 < 5071a1e606b30c0c11278d3c6620cd6a24724cf65071a1e606b30c0c11278d3c6620cd6a24724cf6
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-85.856.8.0-85.85
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 4.13 < 5.10.2375.10.237
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1356.1.135
linuxlinux_kernel>= 6.13 < 6.13.126.13.12

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_msrc3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.