cbcvebase.
CVE-2025-37840
published 2025-05-09

CVE-2025-37840: In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: brcmnand: fix PM resume warning Fixed warning on PM resume as shown below…

PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.29%
21.3th percentile
In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: brcmnand: fix PM resume warning Fixed warning on PM resume as shown below caused due to uninitialized struct nand_operation that checks chip select field : WARN_ON(op->cs >= nanddev_ntargets(&chip->base) [ 14.588522] ------------[ cut here ]------------ [ 14.588529] WARNING: CPU: 0 PID: 1392 at drivers/mtd/nand/raw/internals.h:139 nand_reset_op+0x1e0/0x1f8 [ 14.588553] Modules linked in: bdc udc_core [ 14.588579] CPU: 0 UID: 0 PID: 1392 Comm: rtcwake Tainted: G W 6.14.0-rc4-g5394eea10651 #16 [ 14.588590] Tainted: [W]=WARN [ 14.588593] Hardware name: Broadcom STB (Flattened Device Tree) [ 14.588598] Call trace: [ 14.588604] dump_backtrace from show_stack+0x18/0x1c [ 14.588622] r7:00000009 r6:0000008b r5:60000153 r4:c0fa558c [ 14.588625] show_stack from dump_stack_lvl+0x70/0x7c [ 14.588639] dump_stack_lvl from dump_stack+0x18/0x1c [ 14.588653] r5:c08d40b0 r4:c1003cb0 [ 14.588656] dump_stack from __warn+0x84/0xe4 [ 14.588668] __warn from warn_slowpath_fmt+0x18c/0x194 [ 14.588678] r7:c08d40b0 r6:c1003cb0 r5:00000000 r4:00000000 [ 14.588681] warn_slowpath_fmt from nand_reset_op+0x1e0/0x1f8 [ 14.588695] r8:70c40dff r7:89705f41 r6:36b4a597 r5:c26c9444 r4:c26b0048 [ 14.588697] nand_reset_op from brcmnand_resume+0x13c/0x150 [ 14.588714] r9:00000000 r8:00000000 r7:c24f8010 r6:c228a3f8 r5:c26c94bc r4:c26b0040 [ 14.588717] brcmnand_resume from platform_pm_resume+0x34/0x54 [ 14.588735] r5:00000010 r4:c0840a50 [ 14.588738] platform_pm_resume from dpm_run_callback+0x5c/0x14c [ 14.588757] dpm_run_callback from device_resume+0xc0/0x324 [ 14.588776] r9:c24f8054 r8:c24f80a0 r7:00000000 r6:00000000 r5:00000010 r4:c24f8010 [ 14.588779] device_resume from dpm_resume+0x130/0x160 [ 14.588799] r9:c22539e4 r8:00000010 r7:c22bebb0 r6:c24f8010 r5:c22539dc r4:c22539b0 [ 14.588802] dpm_resume from dpm_resume_end+0x14/0x20 [ 14.588822] r10:c2204e40 r9:00000000 r8:c228a3fc r7:00000000 r6:00000003 r5:c228a414 [ 14.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= 97d90da8a886949f09bb4754843fb0b504956ad2 < 6f567c6a5250e3531cfd9c7ff254ecc2650464fa6f567c6a5250e3531cfd9c7ff254ecc2650464fa
linuxlinux>= 97d90da8a886949f09bb4754843fb0b504956ad2 < 8775581e1c48e1bdd04a893d6f6bbe5128ad0ea78775581e1c48e1bdd04a893d6f6bbe5128ad0ea7
linuxlinux>= 97d90da8a886949f09bb4754843fb0b504956ad2 < fbcb584efa5cd912ff8a151d67b8fe22f4162a85fbcb584efa5cd912ff8a151d67b8fe22f4162a85
linuxlinux>= 97d90da8a886949f09bb4754843fb0b504956ad2 < 9dd161f707ecb7db38e5f529e979a5b6eb565b2d9dd161f707ecb7db38e5f529e979a5b6eb565b2d
linuxlinux>= 97d90da8a886949f09bb4754843fb0b504956ad2 < 9bd51723ab51580e077c91d494c37e80703b85249bd51723ab51580e077c91d494c37e80703b8524
linuxlinux>= 97d90da8a886949f09bb4754843fb0b504956ad2 < 7266066b9469f04ed1d4c0fdddaea1425835eb557266066b9469f04ed1d4c0fdddaea1425835eb55
linuxlinux>= 97d90da8a886949f09bb4754843fb0b504956ad2 < c2eb3cffb0d972c5503e4d48921971c81def0fe5c2eb3cffb0d972c5503e4d48921971c81def0fe5
linuxlinux>= 97d90da8a886949f09bb4754843fb0b504956ad2 < 659b1f29f3e2fd5d751fdf35c5526d1f1c9b3dd2659b1f29f3e2fd5d751fdf35c5526d1f1c9b3dd2
linuxlinux>= 97d90da8a886949f09bb4754843fb0b504956ad2 < ddc210cf8b8a8be68051ad958bf3e2cef6b681c2ddc210cf8b8a8be68051ad958bf3e2cef6b681c2
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 4.16 < 5.4.2935.4.293
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1356.1.135
linuxlinux_kernel>= 5.5 < 5.10.2375.10.237
linuxlinux_kernel>= 6.13 < 6.13.126.13.12

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.