cbcvebase.
CVE-2025-37985
published 2025-05-20

CVE-2025-37985: In the Linux kernel, the following vulnerability has been resolved: USB: wdm: close race between wdm_open and wdm_wwan_port_stop Clearing WDM_WWAN_IN_USE must…

PriorityP414medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.12%
2.3th percentile
In the Linux kernel, the following vulnerability has been resolved: USB: wdm: close race between wdm_open and wdm_wwan_port_stop Clearing WDM_WWAN_IN_USE must be the last action or we can open a chardev whose URBs are still poisoned

Affected

33 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
debianlinux-6.1< linux 6.1.137-1 (bookworm)linux 6.1.137-1 (bookworm)
linuxlinux
linuxlinux>= cac6fb015f719104e60b1c68c15ca5b734f57b9c < b02a3fef3e8c8fe5a0a266f7a14f38cc608fb167b02a3fef3e8c8fe5a0a266f7a14f38cc608fb167
linuxlinux>= cac6fb015f719104e60b1c68c15ca5b734f57b9c < 217fe1fc7d112595a793e02b306710e702eac492217fe1fc7d112595a793e02b306710e702eac492
linuxlinux>= cac6fb015f719104e60b1c68c15ca5b734f57b9c < 54f7f8978af19f899dec80bcc71c8d4855dfbd7254f7f8978af19f899dec80bcc71c8d4855dfbd72
linuxlinux>= cac6fb015f719104e60b1c68c15ca5b734f57b9c < 52ae15c665b5fe5876655aaccc3ef70560b0e31452ae15c665b5fe5876655aaccc3ef70560b0e314
linuxlinux>= cac6fb015f719104e60b1c68c15ca5b734f57b9c < e3c9adc69357fcbe6253a2bc2588ee4bbaaedbe9e3c9adc69357fcbe6253a2bc2588ee4bbaaedbe9
linuxlinux>= cac6fb015f719104e60b1c68c15ca5b734f57b9c < c1846ed4eb527bdfe6b3b7dd2c78e2af4bf98f4fc1846ed4eb527bdfe6b3b7dd2c78e2af4bf98f4f
linuxlinux_kernel
linuxlinux_kernel>= 0 < 6.1.137-16.1.137-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 6.12.27-16.12.27-1
linuxlinux_kernel>= 0 < 5.15.0-144.1575.15.0-144.157
linuxlinux_kernel>= 0 < 6.8.0-100.1006.8.0-100.100
linuxlinux_kernel>= 0 < 6.14.0-22.226.14.0-22.22
linuxlinux_kernel>= 5.14 < 5.15.1815.15.181
linuxlinux_kernel>= 5.16 < 6.1.1366.1.136
linuxlinux_kernel>= 6.13 < 6.14.56.14.5
linuxlinux_kernel>= 6.2 < 6.6.896.6.89
linuxlinux_kernel>= 6.7 < 6.12.266.12.26
msrcazl3_kernel_6.6.85.1-4_on_azure_linux_3.0
msrcazl3_kernel_6.6.92.2-1_on_azure_linux_3.0
ubuntulinux-aws

CVSS provenance

nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian4.7MEDIUM
vendor_msrc4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.