cbcvebase.
CVE-2025-37813
published 2025-05-08

CVE-2025-37813: In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix invalid pointer dereference in Etron workaround This check is performed…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.17%
7.0th percentile
In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix invalid pointer dereference in Etron workaround This check is performed before prepare_transfer() and prepare_ring(), so enqueue can already point at the final link TRB of a segment. And indeed it will, some 0.4% of times this code is called. Then enqueue + 1 is an invalid pointer. It will crash the kernel right away or load some junk which may look like a link TRB and cause the real link TRB to be replaced with a NOOP. This wouldn't end well. Use a functionally equivalent test which doesn't dereference the pointer and always gives correct result. Something has crashed my machine twice in recent days while playing with an Etron HC, and a control transfer stress test ran for confirmation has just crashed it again. The same test passes with this patch applied.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.12.27-1 (forky)linux 6.12.27-1 (forky)
linuxlinux
linuxlinux
linuxlinux>= 5e1c67abc9301d05130b7e267c204e7005503b33 < 0624e29c595b05e7a0e6d1c368f0a05799928e300624e29c595b05e7a0e6d1c368f0a05799928e30
linuxlinux>= 5e1c67abc9301d05130b7e267c204e7005503b33 < 1ea050da5562af9b930d17cbbe9632d30f5df43a1ea050da5562af9b930d17cbbe9632d30f5df43a
linuxlinux>= 6.11.11 < 6.126.12
linuxlinux>= 6.12.2 < 6.12.266.12.26
linuxlinux>= 6.6.66 < 6.6.896.6.89
linuxlinux>= 9258c9ed32294ce3a4b58c9d92fc49ba030d35c9 < bce3055b08e303e28a8751f6073066f5c33a0744bce3055b08e303e28a8751f6073066f5c33a0744
linuxlinux>= fbc0a0c7718a6cb1dc5e0811a4f88a2b1deedfa1 < 142273a49f2c315eabdbdf5a71c15e479b75ca91142273a49f2c315eabdbdf5a71c15e479b75ca91
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.11.11 < 6.126.12
linuxlinux_kernel>= 6.12.2 < 6.12.266.12.26
linuxlinux_kernel>= 6.13 < 6.14.56.14.5
linuxlinux_kernel>= 6.6.66 < 6.6.896.6.89
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.