cbcvebase.
CVE-2025-37780
published 2025-05-01

CVE-2025-37780: In the Linux kernel, the following vulnerability has been resolved: isofs: Prevent the use of too small fid syzbot reported a slab-out-of-bounds Read in…

PriorityP429high7.1CVSS 3.1
AVLACLPRLUINSUCHINAH
EPSS
0.20%
9.9th percentile
In the Linux kernel, the following vulnerability has been resolved: isofs: Prevent the use of too small fid syzbot reported a slab-out-of-bounds Read in isofs_fh_to_parent. [1] The handle_bytes value passed in by the reproducing program is equal to 12. In handle_to_path(), only 12 bytes of memory are allocated for the structure file_handle->f_handle member, which causes an out-of-bounds access when accessing the member parent_block of the structure isofs_fid in isofs, because accessing parent_block requires at least 16 bytes of f_handle. Here, fh_len is used to indirectly confirm that the value of handle_bytes is greater than 3 before accessing parent_block. [1] BUG: KASAN: slab-out-of-bounds in isofs_fh_to_parent+0x1b8/0x210 fs/isofs/export.c:183 Read of size 4 at addr ffff0000cc030d94 by task syz-executor215/6466 CPU: 1 UID: 0 PID: 6466 Comm: syz-executor215 Not tainted 6.14.0-rc7-syzkaller-ga2392f333575 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/12/2025 Call trace: show_stack+0x2c/0x3c arch/arm64/kernel/stacktrace.c:466 (C) __dump_stack lib/dump_stack.c:94 [inline] dump_stack_lvl+0xe4/0x150 lib/dump_stack.c:120 print_address_description mm/kasan/report.c:408 [inline] print_report+0x198/0x550 mm/kasan/report.c:521 kasan_report+0xd8/0x138 mm/kasan/report.c:634 __asan_report_load4_noabort+0x20/0x2c mm/kasan/report_generic.c:380 isofs_fh_to_parent+0x1b8/0x210 fs/isofs/export.c:183 exportfs_decode_fh_raw+0x2dc/0x608 fs/exportfs/expfs.c:523 do_handle_to_path+0xa0/0x198 fs/fhandle.c:257 handle_to_path fs/fhandle.c:385 [inline] do_handle_open+0x8cc/0xb8c fs/fhandle.c:403 __do_sys_open_by_handle_at fs/fhandle.c:443 [inline] __se_sys_open_by_handle_at fs/fhandle.c:434 [inline] __arm64_sys_open_by_handle_at+0x80/0x94 fs/fhandle.c:434 __invoke_syscall arch/arm64/kernel/syscall.c:35 [inline] invoke_syscall+0x98/0x2b8 arch/arm64/kernel/syscall.c:49 el0_svc_common+0x130/0x23c arch/arm64/kernel/syscall.c:132 do_el0_svc+0x48/0x58 arch

Affected

63 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux
linuxlinux>= 0405d4b63d082861f4eaff9d39c78ee9dc34f845 < afbafeddf23db13fe2edb2d5c0bf4bbb13d7881bafbafeddf23db13fe2edb2d5c0bf4bbb13d7881b
linuxlinux>= 0405d4b63d082861f4eaff9d39c78ee9dc34f845 < 4c721a1d9b3c4fcaf59cc9b2281e3ec5a043e1a64c721a1d9b3c4fcaf59cc9b2281e3ec5a043e1a6
linuxlinux>= 0405d4b63d082861f4eaff9d39c78ee9dc34f845 < 24376458138387fb251e782e624c7776e982679624376458138387fb251e782e624c7776e9826796
linuxlinux>= 0fdafdaef796816a9ed0fd7ac812932d569d9beb < 908a76f0b1038035e6ebb4f2293ce079f92e0a02908a76f0b1038035e6ebb4f2293ce079f92e0a02
linuxlinux>= 5.10.237 < 5.10.2585.10.258
linuxlinux>= 5.15.181 < 5.15.2095.15.209
linuxlinux>= 5.4.293 < 5.55.5
linuxlinux>= 56dfffea9fd3be0b3795a9ca6401e133a8427e0b < 0a1af74ae2177bda3aee0837a0546309aa539d0d0a1af74ae2177bda3aee0837a0546309aa539d0d
linuxlinux>= 5e7de55602c61c8ff28db075cc49c8dd6989d7e0 < ee0024f5a7e3c73aa253869fae9650ae054093caee0024f5a7e3c73aa253869fae9650ae054093ca
linuxlinux>= 6.1.135 < 6.1.1756.1.175
linuxlinux>= 6.12.25 < 6.12.886.12.88
linuxlinux>= 6.14.4 < 6.156.15
linuxlinux>= 6.6.88 < 6.6.1406.6.140
linuxlinux>= 63d5a3e207bf315a32c7d16de6c89753a759f95a < 31dbb4ba0f719ae7774e4c0c95172c9bf81692f531dbb4ba0f719ae7774e4c0c95172c9bf81692f5
linuxlinux>= 952e7a7e317f126d0a2b879fc531b716932d5ffa < bb0988ed4f2e26d59bbb58f644cb3a55b7521e21bb0988ed4f2e26d59bbb58f644cb3a55b7521e21
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.