CVE-2025-37997 — Improper Locking in Linux
Severity
5.5MEDIUMNVD
OSV8.8OSV7.8OSV5.9OSV4.7
EPSS
0.1%
top 76.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 29
Latest updateSep 2
Description
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ipset: fix region locking in hash types
Region locking introduced in v5.6-rc4 contained three macros to handle
the region locks: ahash_bucket_start(), ahash_bucket_end() which gave
back the start and end hash bucket values belonging to a given region
lock and ahash_region() which should give back the region lock belonging
to a given hash bucket. The latter was incorrect which can lead to a
race condition between the…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages4 packages
▶CVEListV5linux/linux5dd9488ae41070b69d2f4acb580f77db5705f9ca — 00cfc5fad1491796942a948808afb968a0a3f35b+9
Also affects: Debian Linux 11.0