PT-2025-20339 · Linux+8 · Linux Kernel+8

CVE-2025-37810

·

Publicado

2025-05-08

·

Atualizado

2026-08-25

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A vulnerability in the Linux kernel has been resolved. The issue is related to the USB gadget functionality, specifically in the dwc3 driver. The problem occurs when the event count read from the DWC3 GEVNTCOUNT register exceeds the event buffer length, leading to an out-of-bounds access when copying the event using memcpy(). This can cause a kernel crash, as indicated by the crash log. The vulnerability is mitigated by adding a check to ensure the event count does not exceed the event buffer length.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

DoS

Memory Corruption

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025:16354
ALSA-2025:16398
BDU:2025-10599
CVE-2025-37810
DLA-4178-1
DLA-4193-1
ECHO-D089-024A-5FBB
INFSA-2025_16398
MGASA-2025-0182
MGASA-2025-0183
OESA-2025-1869
OESA-2025-1870
OESA-2025-1874
OESA-2025-2698
OESA-2025-2699
RHSA-2025:16354
RHSA-2025:17122
RHSA-2025:17123
RHSA-2025:18054
RHSA-2025:18098
RHSA-2025_16398
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:02254-1
SUSE-SU-2025:02307-1
SUSE-SU-2025:02333-1
SUSE-SU-2025:02334-1
SUSE-SU-2025:02923-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_02000-1
SUSE-SU-2025_02254-1
SUSE-SU-2025_02307-1
SUSE-SU-2025_02333-1
SUSE-SU-2025_02334-1
USN-7594-1
USN-7594-2
USN-7594-3
USN-7654-1
USN-7654-2
USN-7654-3
USN-7654-4
USN-7654-5
USN-7655-1
USN-7686-1
USN-7711-1
USN-7712-1
USN-7712-2
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Produtos afetados

Almalinux
Astra Linux
Debian
Linuxmint
Linux Kernel
Red Hat
Red Os
Suse
Ubuntu