PT-2025-20353 · Linux+6 · Linux Kernel+6

·

CVE-2025-37824

·

Publicado

2025-04-23

·

Atualizado

2026-08-25

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 6.15.0-rc1-syzkaller-00246-g900241a5cc15
Description A NULL pointer dereference issue has been identified in the Linux kernel, specifically in the tipc mon reinit self() function. This issue arises due to a racing condition between a workqueue created when enabling a bearer and another thread created when disabling the bearer immediately after. The tipc mon reinit self() function attempts to access a NULL pointer, leading to a general protection fault. Technical details about the issue include the involvement of the tipc disc timeout() and bearer disable() functions, as well as the write lock bh() and write unlock bh() locking mechanisms.
Recommendations To resolve this issue, update the Linux kernel to a version that includes the fix for the NULL pointer dereference in tipc mon reinit self(). As a temporary workaround, consider disabling the tipc mon reinit self() function until a patch is available. Restrict access to the vulnerable tipc module to minimize the risk of exploitation.

Exploit

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-12149
CVE-2025-37824
DLA-4178-1
DLA-4193-1
ECHO-972D-7BBD-D3E9
MGASA-2025-0182
MGASA-2025-0183
OESA-2025-1878
OESA-2025-1879
OESA-2025-1880
SUSE-SU-2025:01919-1
SUSE-SU-2025:01951-1
SUSE-SU-2025:01964-1
SUSE-SU-2025:01965-1
SUSE-SU-2025:01967-1
SUSE-SU-2025:01972-1
SUSE-SU-2025:02000-1
SUSE-SU-2025:20408-1
SUSE-SU-2025:20413-1
SUSE-SU-2025:20419-1
SUSE-SU-2025:20421-1
SUSE-SU-2025_01951-1
SUSE-SU-2025_01964-1
SUSE-SU-2025_01965-1
SUSE-SU-2025_01967-1
SUSE-SU-2025_01972-1
SUSE-SU-2025_02000-1
USN-7594-1
USN-7594-2
USN-7594-3
USN-7654-1
USN-7654-2
USN-7654-3
USN-7654-4
USN-7654-5
USN-7655-1
USN-7686-1
USN-7711-1
USN-7712-1
USN-7712-2
USN-8028-1
USN-8028-2
USN-8028-3
USN-8028-4
USN-8028-5
USN-8028-6
USN-8028-7
USN-8028-8
USN-8031-1
USN-8031-2
USN-8031-3
USN-8052-1
USN-8052-2
USN-8074-1
USN-8074-2
USN-8126-1

Produtos afetados

Astra Linux
Debian
Linuxmint
Linux Kernel
Red Os
Suse
Ubuntu