cbcvebase.
CVE-2025-37883
published 2025-05-09

CVE-2025-37883: In the Linux kernel, the following vulnerability has been resolved: s390/sclp: Add check for get_zeroed_page() Add check for the return value of…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.25%
16.2th percentile
In the Linux kernel, the following vulnerability has been resolved: s390/sclp: Add check for get_zeroed_page() Add check for the return value of get_zeroed_page() in sclp_console_init() to prevent null pointer dereference. Furthermore, to solve the memory leak caused by the loop allocation, add a free helper to do the free job.

Affected

32 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
debianlinux-6.1< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
linuxlinux
linuxlinux>= 4c8f4794b61e89dd68f96cfc23a9d9b6c25be420 < e1e00dc45648125ef7cb87ebc3b581ac224e7b39e1e00dc45648125ef7cb87ebc3b581ac224e7b39
linuxlinux>= 4c8f4794b61e89dd68f96cfc23a9d9b6c25be420 < 397254706eba9d8f99fd237feede7ab3169a7f9a397254706eba9d8f99fd237feede7ab3169a7f9a
linuxlinux>= 4c8f4794b61e89dd68f96cfc23a9d9b6c25be420 < 28e5a867aa542e369e211c2baba7044228809a9928e5a867aa542e369e211c2baba7044228809a99
linuxlinux>= 4c8f4794b61e89dd68f96cfc23a9d9b6c25be420 < 3b3aa72636a6205933609ec274a8747720c1ee3f3b3aa72636a6205933609ec274a8747720c1ee3f
linuxlinux>= 4c8f4794b61e89dd68f96cfc23a9d9b6c25be420 < f69f8a93aacf6e99af7b1cc992d8ca2cc07b96fbf69f8a93aacf6e99af7b1cc992d8ca2cc07b96fb
linuxlinux>= 4c8f4794b61e89dd68f96cfc23a9d9b6c25be420 < 3db42c75a921854a99db0a2775814fef97415bac3db42c75a921854a99db0a2775814fef97415bac
linuxlinux_kernel< 5.15.1815.15.181
linuxlinux_kernel>= 0 < 6.1.137-16.1.137-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 5.16 < 6.1.1366.1.136
linuxlinux_kernel>= 6.13 < 6.14.56.14.5
linuxlinux_kernel>= 6.2 < 6.6.896.6.89
linuxlinux_kernel>= 6.7 < 6.12.266.12.26
msrcazl3_kernel_6.6.85.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-aws-6.8

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.