cbcvebase.
CVE-2025-37815
published 2025-05-08

CVE-2025-37815: In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: Fix Kernel panic during IRQ handler registration Resolve kernel…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.16%
6.0th percentile
In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: Fix Kernel panic during IRQ handler registration Resolve kernel panic while accessing IRQ handler associated with the generated IRQ. This is done by acquiring the spinlock and storing the current interrupt state before handling the interrupt request using generic_handle_irq. A previous fix patch was submitted where 'generic_handle_irq' was replaced with 'handle_nested_irq'. However, this change also causes the kernel panic where after determining which GPIO triggered the interrupt and attempting to call handle_nested_irq with the mapped IRQ number, leads to a failure in locating the registered handler.

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
debianlinux-6.1< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
linuxlinux
linuxlinux>= 194f9f94a5169547d682e9bbcc5ae6d18a564735 < 4e02059dc91068bc5017b8546f9ec3b930f6d6a64e02059dc91068bc5017b8546f9ec3b930f6d6a6
linuxlinux>= 194f9f94a5169547d682e9bbcc5ae6d18a564735 < 18eb77c75ed01439f96ae5c0f33461eb5134b90718eb77c75ed01439f96ae5c0f33461eb5134b907
linuxlinux>= 25692750c0259c5b65afec467d97201a485e8a00 < 62957f58ab3aa7fa792dc6ff3575624062539a4d62957f58ab3aa7fa792dc6ff3575624062539a4d
linuxlinux>= 47d3749ec0cb56b7b98917c190a8c10cb54216fd < 12cc2193f2b9548e8ea5fbce8201b44158222edf12cc2193f2b9548e8ea5fbce8201b44158222edf
linuxlinux>= 6.1.125 < 6.1.1366.1.136
linuxlinux>= 6.12.10 < 6.12.266.12.26
linuxlinux>= 6.6.72 < 6.6.896.6.89
linuxlinux>= 79aef6187e16b2d32307c8ff610e9e04f7f86e1f < 1263d5f581908602c618c6665e683c4436383a091263d5f581908602c618c6665e683c4436383a09
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.137-16.1.137-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.1.125 < 6.1.1366.1.136
linuxlinux_kernel>= 6.12.10 < 6.12.266.12.26
linuxlinux_kernel>= 6.13.1 < 6.14.56.14.5
linuxlinux_kernel>= 6.6.72 < 6.6.896.6.89
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.