cbcvebase.
CVE-2025-37984
published 2025-05-20

CVE-2025-37984: In the Linux kernel, the following vulnerability has been resolved: crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() Herbert notes that…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.15%
5.1th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() Herbert notes that DIV_ROUND_UP() may overflow unnecessarily if an ecdsa implementation's ->key_size() callback returns an unusually large value. Herbert instead suggests (for a division by 8): X / 8 + !!(X & 7) Based on this formula, introduce a generic DIV_ROUND_UP_POW2() macro and use it in lieu of DIV_ROUND_UP() for ->key_size() return values. Additionally, use the macro in ecc_digits_from_bytes(), whose "nbytes" parameter is a ->key_size() return value in some instances, or a user-specified ASN.1 length in the case of ecdsa_get_signature_rs().

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.16.3-1 (forky)linux 6.16.3-1 (forky)
linuxlinux
linuxlinux>= 55779f26eab9af12474a447001bd17070f055712 < f02f0218be412cff1c844addf58e002071be298bf02f0218be412cff1c844addf58e002071be298b
linuxlinux>= 6.6.70 < 6.6.996.6.99
linuxlinux>= c6ab5c915da460c0397960af3c308386c3f3247b < f2133b849ff273abddb6da622daddd8f6f6fa448f2133b849ff273abddb6da622daddd8f6f6fa448
linuxlinux>= c6ab5c915da460c0397960af3c308386c3f3247b < 921b8167f10708e38080f84e195cdc68a7a561f1921b8167f10708e38080f84e195cdc68a7a561f1
linuxlinux>= c6ab5c915da460c0397960af3c308386c3f3247b < b16510a530d1e6ab9683f04f8fb34f2e0f538275b16510a530d1e6ab9683f04f8fb34f2e0f538275
linuxlinux_kernel>= 0 < 6.12.41-16.12.41-1
linuxlinux_kernel>= 0 < 6.16.3-16.16.3-1
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 6.10 < 6.12.396.12.39
linuxlinux_kernel>= 6.13 < 6.14.56.14.5
linuxlinux_kernel>= 6.6.70 < 6.6.996.6.99
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0
ubuntulinux-aws
ubuntulinux-aws-6.8
ubuntulinux-gkeop
ubuntulinux-nvidia
ubuntulinux-nvidia-6.8
ubuntulinux-oracle
ubuntulinux-oracle-6.8
ubuntulinux-raspi-realtime
ubuntulinux-realtime

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_msrc6.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
vendor_ubuntu3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.