cbcvebase.
CVE-2025-37885
published 2025-05-09

CVE-2025-37885: In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Reset IRTE to host control if *new* route isn't postable Restore an IRTE back to…

PriorityP339high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
19.7th percentile
In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Reset IRTE to host control if *new* route isn't postable Restore an IRTE back to host control (remapped or posted MSI mode) if the *new* GSI route prevents posting the IRQ directly to a vCPU, regardless of the GSI routing type. Updating the IRTE if and only if the new GSI is an MSI results in KVM leaving an IRTE posting to a vCPU. The dangling IRTE can result in interrupts being incorrectly delivered to the guest, and in the worst case scenario can result in use-after-free, e.g. if the VM is torn down, but the underlying host IRQ isn't freed.

Affected

38 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
debianlinux-6.1< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
linuxlinux
linuxlinux>= efc644048ecde54f016011fe10110addd0de348f < e5f2dee9f7fcd2ff4b97869f3c66a0d89c167769e5f2dee9f7fcd2ff4b97869f3c66a0d89c167769
linuxlinux>= efc644048ecde54f016011fe10110addd0de348f < 116c7d35b8f72eac383b9fd371d7c1a8ffc2968b116c7d35b8f72eac383b9fd371d7c1a8ffc2968b
linuxlinux>= efc644048ecde54f016011fe10110addd0de348f < 023816bd5fa46fab94d1e7917fe131b79ed1fb41023816bd5fa46fab94d1e7917fe131b79ed1fb41
linuxlinux>= efc644048ecde54f016011fe10110addd0de348f < 3481fd96d801715942b6f69fe251133128156f303481fd96d801715942b6f69fe251133128156f30
linuxlinux>= efc644048ecde54f016011fe10110addd0de348f < b5de7ac74f69603ad803c524b840bffd36368fc3b5de7ac74f69603ad803c524b840bffd36368fc3
linuxlinux>= efc644048ecde54f016011fe10110addd0de348f < 3066ec21d1a33896125747f68638725f456308db3066ec21d1a33896125747f68638725f456308db
linuxlinux>= efc644048ecde54f016011fe10110addd0de348f < 9bcac97dc42d2f4da8229d18feb0fe2b1ce523a29bcac97dc42d2f4da8229d18feb0fe2b1ce523a2
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.137-16.1.137-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 4.4 < 5.10.2375.10.237
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1366.1.136
linuxlinux_kernel>= 6.13 < 6.14.56.14.5

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.