cbcvebase.
CVE-2025-37963
published 2025-05-20

CVE-2025-37963: In the Linux kernel, the following vulnerability has been resolved: arm64: bpf: Only mitigate cBPF programs loaded by unprivileged users Support for eBPF…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.17%
6.2th percentile
In the Linux kernel, the following vulnerability has been resolved: arm64: bpf: Only mitigate cBPF programs loaded by unprivileged users Support for eBPF programs loaded by unprivileged users is typically disabled. This means only cBPF programs need to be mitigated for BHB. In addition, only mitigate cBPF programs that were loaded by an unprivileged user. Privileged users can also load the same program via eBPF, making the mitigation pointless.

Affected

36 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
debianlinux-6.1< linux 6.1.140-1 (bookworm)linux 6.1.140-1 (bookworm)
linuxlinux
linuxlinux>= 0be7320a635c2e434e8b67e0e9474a85ceb421c4 < 038866e01ea5e5a3d948898ac216e531e7848669038866e01ea5e5a3d948898ac216e531e7848669
linuxlinux>= 0be7320a635c2e434e8b67e0e9474a85ceb421c4 < df53d418709205450a02bb4d71cbfb4ff86f2c1edf53d418709205450a02bb4d71cbfb4ff86f2c1e
linuxlinux>= 0be7320a635c2e434e8b67e0e9474a85ceb421c4 < 6e52d043f7dbf1839a24a3fab2b12b0d3839de7a6e52d043f7dbf1839a24a3fab2b12b0d3839de7a
linuxlinux>= 0be7320a635c2e434e8b67e0e9474a85ceb421c4 < 80251f62028f1ab2e09be5ca3123f84e8b00389a80251f62028f1ab2e09be5ca3123f84e8b00389a
linuxlinux>= 0be7320a635c2e434e8b67e0e9474a85ceb421c4 < e5f5100f1c64ac6c72671b2cf6b46542fce93706e5f5100f1c64ac6c72671b2cf6b46542fce93706
linuxlinux>= 0be7320a635c2e434e8b67e0e9474a85ceb421c4 < 477481c4348268136227348984b6699d6370b685477481c4348268136227348984b6699d6370b685
linuxlinux>= 0be7320a635c2e434e8b67e0e9474a85ceb421c4 < f300769ead032513a68e4a02e806393402e626f8f300769ead032513a68e4a02e806393402e626f8
linuxlinux_kernel< 5.10.2395.10.239
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.244-15.10.244-1
linuxlinux_kernel>= 0 < 6.1.140-16.1.140-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 6.12.29-16.12.29-1
linuxlinux_kernel>= 0 < 5.15.0-156.1665.15.0-156.166
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 5.11 < 5.15.1865.15.186
linuxlinux_kernel>= 5.16 < 6.1.1396.1.139
linuxlinux_kernel>= 6.13 < 6.14.76.14.7
linuxlinux_kernel>= 6.2 < 6.6.916.6.91
linuxlinux_kernel>= 6.7 < 6.12.296.12.29
msrcazl3_kernel_6.6.85.1-4_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.8HIGH
vendor_ubuntu7.8HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.