cbcvebase.
CVE-2025-37838
published 2025-04-18

CVE-2025-37838: In the Linux kernel, the following vulnerability has been resolved: HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.21%
10.8th percentile
In the Linux kernel, the following vulnerability has been resolved: HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition In the ssi_protocol_probe() function, &ssi->work is bound with ssip_xmit_work(), In ssip_pn_setup(), the ssip_pn_xmit() function within the ssip_pn_ops structure is capable of starting the work. If we remove the module which will call ssi_protocol_remove() to make a cleanup, it will free ssi through kfree(ssi), while the work mentioned above will be used. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | ssip_xmit_work ssi_protocol_remove | kfree(ssi); | | struct hsi_client *cl = ssi->cl; | // use ssi Fix it by ensuring that the work is canceled before proceeding with the cleanup in ssi_protocol_remove().

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= df26d639e2f4628732a8da5a0f71e4e652ce809b < d03abc1c2b21324550fa71e12d53e7d3498e0af6d03abc1c2b21324550fa71e12d53e7d3498e0af6
linuxlinux>= df26d639e2f4628732a8da5a0f71e4e652ce809b < 4a8c29beb8a02b5a0a9d77d608aa14b6f88a6b864a8c29beb8a02b5a0a9d77d608aa14b6f88a6b86
linuxlinux>= df26d639e2f4628732a8da5a0f71e4e652ce809b < 72972552d0d0bfeb2dec5daf343a19018db36ffa72972552d0d0bfeb2dec5daf343a19018db36ffa
linuxlinux>= df26d639e2f4628732a8da5a0f71e4e652ce809b < d58493832e284f066e559b8da5ab20c15a2801d3d58493832e284f066e559b8da5ab20c15a2801d3
linuxlinux>= df26d639e2f4628732a8da5a0f71e4e652ce809b < 58eb29dba712ab0f13af59ca2fe545f5ce360e7858eb29dba712ab0f13af59ca2fe545f5ce360e78
linuxlinux>= df26d639e2f4628732a8da5a0f71e4e652ce809b < ae5a6a0b425e8f76a9f0677e50796e494e89b088ae5a6a0b425e8f76a9f0677e50796e494e89b088
linuxlinux>= df26d639e2f4628732a8da5a0f71e4e652ce809b < 834e602d0cc7c743bfce734fad4a46cefc0f9ab1834e602d0cc7c743bfce734fad4a46cefc0f9ab1
linuxlinux>= df26d639e2f4628732a8da5a0f71e4e652ce809b < 4b4194c9a7a8f92db39e8e86c85f4fb12ebbec4f4b4194c9a7a8f92db39e8e86c85f4fb12ebbec4f
linuxlinux>= df26d639e2f4628732a8da5a0f71e4e652ce809b < e3f88665a78045fe35c7669d2926b8d97b892c11e3f88665a78045fe35c7669d2926b8d97b892c11
linuxlinux_kernel< 6.1.1356.1.135
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-87.886.8.0-87.88
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 0 < 4.4.0-274.3084.4.0-274.308
linuxlinux_kernel>= 0 < 4.15.0-243.2554.15.0-243.255
linuxlinux_kernel>= 0 < 5.4.0-223.2435.4.0-223.243
linuxlinux_kernel>= 6.13 < 6.13.126.13.12
linuxlinux_kernel>= 6.14 < 6.14.36.14.3

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.