cbcvebase.
CVE-2025-37912
published 2025-05-20

CVE-2025-37912: In the Linux kernel, the following vulnerability has been resolved: ice: Check VF VSI Pointer Value in ice_vc_add_fdir_fltr() As mentioned in the commit…

PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.18%
7.3th percentile
In the Linux kernel, the following vulnerability has been resolved: ice: Check VF VSI Pointer Value in ice_vc_add_fdir_fltr() As mentioned in the commit baeb705fd6a7 ("ice: always check VF VSI pointer values"), we need to perform a null pointer check on the return value of ice_get_vf_vsi() before using it.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
debianlinux-6.1< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 5.15.172 < 5.15.1825.15.182
linuxlinux>= 6.1.103 < 6.1.1386.1.138
linuxlinux>= 6.10.3 < 6.116.11
linuxlinux>= 6.6.44 < 6.6.906.6.90
linuxlinux>= 6ebbe97a488179f5dc85f2f1e0c89b486e99ee97 < 073791e9cfe6e4a11a6d85816ba87b1aa207493e073791e9cfe6e4a11a6d85816ba87b1aa207493e
linuxlinux>= 6ebbe97a488179f5dc85f2f1e0c89b486e99ee97 < f68237982dc012230550f4ecf7ce286a9c37ddc9f68237982dc012230550f4ecf7ce286a9c37ddc9
linuxlinux>= 6ebbe97a488179f5dc85f2f1e0c89b486e99ee97 < 425c5f266b2edeee0ce16fedd8466410cdcfcfe3425c5f266b2edeee0ce16fedd8466410cdcfcfe3
linuxlinux>= 8e02cd98a6e24389d476e28436d41e620ed8e559 < 0561f2e374c3732b90e50f0a244791a4308ec67e0561f2e374c3732b90e50f0a244791a4308ec67e
linuxlinux>= d62389073a5b937413e2d1bc1da06ccff5103c0c < eae60cfe25d022d7f0321dba4cc23ad8e87ade48eae60cfe25d022d7f0321dba4cc23ad8e87ade48
linuxlinux>= e81b674ead8e2172b2a69e7b45e079239ace4dbc < a32dcc3b8293600ddc4024731b4d027d4de061a4a32dcc3b8293600ddc4024731b4d027d4de061a4
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.140-16.1.140-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-24.246.14.0-24.24
linuxlinux_kernel>= 5.15.172 < 5.15.1825.15.182
linuxlinux_kernel>= 6.1.103 < 6.1.1386.1.138
linuxlinux_kernel>= 6.10.3 < 6.12.286.12.28

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.