cbcvebase.
CVE-2025-37875
published 2025-05-09

CVE-2025-37875: In the Linux kernel, the following vulnerability has been resolved: igc: fix PTM cycle trigger logic Writing to clear the PTM status 'valid' bit while the PTM…

PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.0th percentile
In the Linux kernel, the following vulnerability has been resolved: igc: fix PTM cycle trigger logic Writing to clear the PTM status 'valid' bit while the PTM cycle is triggered results in unreliable PTM operation. To fix this, clear the PTM 'trigger' and status after each PTM transaction. The issue can be reproduced with the following: $ sudo phc2sys -R 1000 -O 0 -i tsn0 -m Note: 1000 Hz (-R 1000) is unrealistically large, but provides a way to quickly reproduce the issue. PHC2SYS exits with: "ioctl PTP_OFFSET_PRECISE: Connection timed out" when the PTM transaction fails This patch also fixes a hang in igc_probe() when loading the igc driver in the kdump kernel on systems supporting PTM. The igc driver running in the base kernel enables PTM trigger in igc_probe(). Therefore the driver is always in PTM trigger mode, except in brief periods when manually triggering a PTM cycle. When a crash occurs, the NIC is reset while PTM trigger is enabled. Due to a hardware problem, the NIC is subsequently in a bad busmaster state and doesn't handle register reads/writes. When running igc_probe() in the kdump kernel, the first register access to a NIC register hangs driver probing and ultimately breaks kdump. With this patch, igc has PTM trigger disabled most of the time, and the trigger is only enabled for very brief (10 - 100 us) periods when manually triggering a PTM cycle. Chances that a crash occurs during a PTM trigger are not 0, but extremely reduced.

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= a90ec84837325df4b9a6798c2cc0df202b5680bd < c1f174edaccc5a00f8e218c42a0aa9156efd5f76c1f174edaccc5a00f8e218c42a0aa9156efd5f76
linuxlinux>= a90ec84837325df4b9a6798c2cc0df202b5680bd < 0c03e4fbe1321697d9d04587e21e416705e1b19f0c03e4fbe1321697d9d04587e21e416705e1b19f
linuxlinux>= a90ec84837325df4b9a6798c2cc0df202b5680bd < 16194ca3f3b4448a062650c869a7b3b206c6f5d316194ca3f3b4448a062650c869a7b3b206c6f5d3
linuxlinux>= a90ec84837325df4b9a6798c2cc0df202b5680bd < f3516229cd12dcd45f23ed01adab17e8772b1bd5f3516229cd12dcd45f23ed01adab17e8772b1bd5
linuxlinux>= a90ec84837325df4b9a6798c2cc0df202b5680bd < 31959e06143692f7e02b8eef7d7d6ac64563790631959e06143692f7e02b8eef7d7d6ac645637906
linuxlinux>= a90ec84837325df4b9a6798c2cc0df202b5680bd < 8e404ad95d2c10c261e2ef6992c7c12dde03df0e8e404ad95d2c10c261e2ef6992c7c12dde03df0e
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 5.15 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1356.1.135
linuxlinux_kernel>= 6.13 < 6.14.46.14.4
linuxlinux_kernel>= 6.2 < 6.6.886.6.88
linuxlinux_kernel>= 6.7 < 6.12.256.12.25
msrcazl3_kernel_6.6.85.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0
ubuntulinux-aws

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.