cbcvebase.
CVE-2025-37812
published 2025-05-08

CVE-2025-37812: In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: Fix deadlock when using NCM gadget The cdns3 driver has the same NCM deadlock…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.9th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: Fix deadlock when using NCM gadget The cdns3 driver has the same NCM deadlock as fixed in cdnsp by commit 58f2fcb3a845 ("usb: cdnsp: Fix deadlock issue during using NCM gadget"). Under PREEMPT_RT the deadlock can be readily triggered by heavy network traffic, for example using "iperf --bidir" over NCM ethernet link. The deadlock occurs because the threaded interrupt handler gets preempted by a softirq, but both are protected by the same spinlock. Prevent deadlock by disabling softirq during threaded irq handler.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
debianlinux-6.1< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
linuxlinux
linuxlinux>= 7733f6c32e36ff9d7adadf40001039bf219b1cbe < eebfb64c624fc738b669100173344fb441c5e719eebfb64c624fc738b669100173344fb441c5e719
linuxlinux>= 7733f6c32e36ff9d7adadf40001039bf219b1cbe < 59a760e4796a3cd88d8b9d7706e0a638de67775159a760e4796a3cd88d8b9d7706e0a638de677751
linuxlinux>= 7733f6c32e36ff9d7adadf40001039bf219b1cbe < b96239582531775f2fdcb14de29bdb6870fd4c8cb96239582531775f2fdcb14de29bdb6870fd4c8c
linuxlinux>= 7733f6c32e36ff9d7adadf40001039bf219b1cbe < c27db84ed44e50ff90d9e3a2a25fae2e0a0fa015c27db84ed44e50ff90d9e3a2a25fae2e0a0fa015
linuxlinux>= 7733f6c32e36ff9d7adadf40001039bf219b1cbe < 48a62deb857f0694f611949015e70ad194d9715948a62deb857f0694f611949015e70ad194d97159
linuxlinux>= 7733f6c32e36ff9d7adadf40001039bf219b1cbe < 74cd6e408a4c010e404832f0e4609d29bf1d0c4174cd6e408a4c010e404832f0e4609d29bf1d0c41
linuxlinux>= 7733f6c32e36ff9d7adadf40001039bf219b1cbe < 09e90a9689a4aac7a2f726dc2aa472b0b37937b709e90a9689a4aac7a2f726dc2aa472b0b37937b7
linuxlinux>= 7733f6c32e36ff9d7adadf40001039bf219b1cbe < a1059896f2bfdcebcdc7153c3be2307ea319501fa1059896f2bfdcebcdc7153c3be2307ea319501f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.137-16.1.137-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1366.1.136
linuxlinux_kernel>= 5.4 < 5.4.2935.4.293
linuxlinux_kernel>= 5.5 < 5.10.2375.10.237
linuxlinux_kernel>= 6.13 < 6.14.56.14.5

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.