cbcvebase.
CVE-2025-37997
published 2025-05-29

CVE-2025-37997: In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix region locking in hash types Region locking introduced in v5.6-rc4…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.7th percentile
In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix region locking in hash types Region locking introduced in v5.6-rc4 contained three macros to handle the region locks: ahash_bucket_start(), ahash_bucket_end() which gave back the start and end hash bucket values belonging to a given region lock and ahash_region() which should give back the region lock belonging to a given hash bucket. The latter was incorrect which can lead to a race condition between the garbage collector and adding new elements when a hash type of set is defined with timeouts.

Affected

46 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 6.1.139-1 (bookworm)linux 6.1.139-1 (bookworm)
debianlinux-6.1< linux 6.1.139-1 (bookworm)linux 6.1.139-1 (bookworm)
googlechrome_chrome
linuxlinux
linuxlinux
linuxlinux>= 5.4.24 < 5.4.2945.4.294
linuxlinux>= 5.5.8 < 5.65.6
linuxlinux>= 5dd9488ae41070b69d2f4acb580f77db5705f9ca < 00cfc5fad1491796942a948808afb968a0a3f35b00cfc5fad1491796942a948808afb968a0a3f35b
linuxlinux>= f66ee0410b1c3481ee75e5db9b34547b4d582465 < 226ce0ec38316d9e3739e73a64b6b8304646c658226ce0ec38316d9e3739e73a64b6b8304646c658
linuxlinux>= f66ee0410b1c3481ee75e5db9b34547b4d582465 < 82c1eb32693bc48251d92532975e19160987e5b982c1eb32693bc48251d92532975e19160987e5b9
linuxlinux>= f66ee0410b1c3481ee75e5db9b34547b4d582465 < aa77294b0f73bb8265987591460cd25b8722c3dfaa77294b0f73bb8265987591460cd25b8722c3df
linuxlinux>= f66ee0410b1c3481ee75e5db9b34547b4d582465 < a3dfec485401943e315c394c29afe2db8f9481d6a3dfec485401943e315c394c29afe2db8f9481d6
linuxlinux>= f66ee0410b1c3481ee75e5db9b34547b4d582465 < e2ab67672b2288521a6146034a971f9a82ffc5c5e2ab67672b2288521a6146034a971f9a82ffc5c5
linuxlinux>= f66ee0410b1c3481ee75e5db9b34547b4d582465 < 6e002ecc1c8cfdfc866b9104ab7888da54613e596e002ecc1c8cfdfc866b9104ab7888da54613e59
linuxlinux>= f66ee0410b1c3481ee75e5db9b34547b4d582465 < 8478a729c0462273188263136880480729e9efca8478a729c0462273188263136880480729e9efca
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_msrc7.0HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.