CVE-2025-37756Improper Input Validation in Linux

Severity
5.5MEDIUMNVD
OSV8.8OSV4.7
EPSS
0.0%
top 93.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 1
Latest updateNov 21

Description

In the Linux kernel, the following vulnerability has been resolved: net: tls: explicitly disallow disconnect syzbot discovered that it can disconnect a TLS socket and then run into all sort of unexpected corner cases. I have a vague recollection of Eric pointing this out to us a long time ago. Supporting disconnect is really hard, for one thing if offload is enabled we'd need to wait for all packets to be _acked_. Disconnect is not commonly used, disallow it. The immediate problem syzbot run

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages9 packages

Also affects: Debian Linux 11.0

Patches

🔴Vulnerability Details

26
OSV
linux-oracle-6.8 vulnerabilities2025-10-15
OSV
linux-azure-6.8 vulnerabilities2025-10-14
OSV
linux-azure vulnerabilities2025-10-08
OSV
linux-aws-6.8 vulnerabilities2025-10-08
OSV
linux-azure-nvidia vulnerabilities2025-10-08

📋Vendor Advisories

29
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2025-132232025-11-21
Ubuntu
Linux kernel (Oracle) vulnerabilities2025-10-15
Ubuntu
Linux kernel (Azure) vulnerabilities2025-10-14
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2025-377562025-10-10
Ubuntu
Linux kernel (AWS) vulnerabilities2025-10-08