cbcvebase.
CVE-2025-37940
published 2025-05-20

CVE-2025-37940: In the Linux kernel, the following vulnerability has been resolved: ftrace: Add cond_resched() to ftrace_graph_set_hash() When the kernel contains a large…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.13%
3.2th percentile
In the Linux kernel, the following vulnerability has been resolved: ftrace: Add cond_resched() to ftrace_graph_set_hash() When the kernel contains a large number of functions that can be traced, the loop in ftrace_graph_set_hash() may take a lot of time to execute. This may trigger the softlockup watchdog. Add cond_resched() within the loop to allow the kernel to remain responsive even when processing a large number of functions. This matches the cond_resched() that is used in other locations of the code that iterates over all functions that can be traced.

Affected

39 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
debianlinux-6.1< linux 6.1.135-1 (bookworm)linux 6.1.135-1 (bookworm)
linuxlinux
linuxlinux>= b9b0c831bed2682c2e3e9f5420fb6985549ef020 < e5b4ae6f01d4a510d5725eca7254519a1093920de5b4ae6f01d4a510d5725eca7254519a1093920d
linuxlinux>= b9b0c831bed2682c2e3e9f5420fb6985549ef020 < 618655d54c5f8af5d57b77491d08c0f0ff77d114618655d54c5f8af5d57b77491d08c0f0ff77d114
linuxlinux>= b9b0c831bed2682c2e3e9f5420fb6985549ef020 < dd38803c9088b848c6b56f4f6d7efc4497bfde61dd38803c9088b848c6b56f4f6d7efc4497bfde61
linuxlinux>= b9b0c831bed2682c2e3e9f5420fb6985549ef020 < 8dd7d7280357596ba63dfdb4c1725d9dd24bd42a8dd7d7280357596ba63dfdb4c1725d9dd24bd42a
linuxlinux>= b9b0c831bed2682c2e3e9f5420fb6985549ef020 < 5d336ac215e5c76e43ef4bca9ba699835e53e2fd5d336ac215e5c76e43ef4bca9ba699835e53e2fd
linuxlinux>= b9b0c831bed2682c2e3e9f5420fb6985549ef020 < 1fce9574b9d515bcb8a75379a8053e18602424e31fce9574b9d515bcb8a75379a8053e18602424e3
linuxlinux>= b9b0c831bed2682c2e3e9f5420fb6985549ef020 < 4429535acab750d963fdc3dfcc9e0eee42f4d5994429535acab750d963fdc3dfcc9e0eee42f4d599
linuxlinux>= b9b0c831bed2682c2e3e9f5420fb6985549ef020 < 72be43ff061a889c6ee648a330a42486cafa15a672be43ff061a889c6ee648a330a42486cafa15a6
linuxlinux>= b9b0c831bed2682c2e3e9f5420fb6985549ef020 < 42ea22e754ba4f2b86f8760ca27f6f71da2d982c42ea22e754ba4f2b86f8760ca27f6f71da2d982c
linuxlinux_kernel>= 0 < 5.10.237-15.10.237-1
linuxlinux_kernel>= 0 < 6.1.135-16.1.135-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 6.12.25-16.12.25-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 4.11 < 5.4.2935.4.293
linuxlinux_kernel>= 5.11 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1356.1.135
linuxlinux_kernel>= 5.5 < 5.10.2375.10.237
linuxlinux_kernel>= 6.13 < 6.13.126.13.12

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.