CVE-2025-37997Improper Locking in Linux

Severity
5.5MEDIUMNVD
OSV8.8OSV7.8OSV5.9OSV4.7
EPSS
0.1%
top 76.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 29
Latest updateSep 2

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix region locking in hash types Region locking introduced in v5.6-rc4 contained three macros to handle the region locks: ahash_bucket_start(), ahash_bucket_end() which gave back the start and end hash bucket values belonging to a given region lock and ahash_region() which should give back the region lock belonging to a given hash bucket. The latter was incorrect which can lead to a race condition between the

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

NVDlinux/linux_kernel5.4.245.4.294+9
Debianlinux/linux_kernel< 5.10.244-1+3
Ubuntulinux/linux_kernel< 5.15.0-143.153+3
CVEListV5linux/linux5dd9488ae41070b69d2f4acb580f77db5705f9ca00cfc5fad1491796942a948808afb968a0a3f35b+9

Also affects: Debian Linux 11.0

Patches

🔴Vulnerability Details

33
OSV
linux-azure-5.15 vulnerabilities2025-09-02
OSV
linux-azure-fips vulnerabilities2025-08-22
OSV
linux-raspi vulnerabilities2025-08-05
OSV
linux-iot vulnerabilities2025-08-04
OSV
linux-azure vulnerabilities2025-07-30

📋Vendor Advisories

30
Ubuntu
Linux kernel (Azure) vulnerabilities2025-09-02
Ubuntu
Linux kernel (Azure FIPS) vulnerabilities2025-08-22
Ubuntu
Linux kernel (Raspberry Pi) vulnerabilities2025-08-05
Ubuntu
Linux kernel (IoT) vulnerabilities2025-08-04
Ubuntu
Linux kernel (Azure) vulnerabilities2025-07-30
CVE-2025-37997 — Improper Locking in Linux | cvebase