CVE-2025-37787

MEDIUM EPSS 4.6%
Published May 1, 20251y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 1, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: net: dsa: mv88e6xxx: avoid unregistering devlink regions which were never registered Russell King reports that a system with mv88e6xxx dereferences a NULL pointer when unbinding this driver: https://lore.kernel.org/netdev/Z_lRkMlTJ1KQ0kVX@shell.armlinux.org.uk/ The crash seems to be in devlink_region_destroy(), which is not NULL tolerant but is given a NULL devlink global region pointer. At least on some chips, some devlink regions are conditionally registered since the blamed commit, see mv88e6xxx_setup_devlink_regions_global(): if (cond && !cond(chip)) continue; These are MV88E6XXX_REGION_STU and MV88E6XXX_REGION_PVT. If the chip does not have an STU or PVT, it should crash like this. To fix the issue, avoid unregistering those regions which are NULL, i.e. were skipped at mv88e6xxx_setup_devlink_regions_global() time.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
4.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-476 NULL Pointer Dereference Memory Safety

Affected Products 7

VendorProductVersionRange
linuxlinux_kernel*≥5.13  –  <5.15.181
linuxlinux_kernel*≥5.16  –  <6.1.135
linuxlinux_kernel*≥6.2  –  <6.6.88
linuxlinux_kernel*≥6.7  –  <6.12.25
linuxlinux_kernel*≥6.13  –  <6.14.4
linuxlinux_kernel6.15any
linuxlinux_kernel6.15any

References 7

  • git.kernel.org https://git.kernel.org/stable/c/3665695e3572239dc233216f06b41f40cc771889
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5f5e95945bb1e08be7655da6acba648274db457d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8ccdf5e24b276848eefb2755e05ff0f005a0c4a1
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b3c70dfe51f10df60db2646c08cebd24bcdc5247
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bbb80f004f7a90c3dcaacc982c59967457254a05
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c84f6ce918a9e6f4996597cbc62536bbf2247c96
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/3665695e3572239dc233216f06b41f40cc771889
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5f5e95945bb1e08be7655da6acba648274db457d
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8ccdf5e24b276848eefb2755e05ff0f005a0c4a1
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b3c70dfe51f10df60db2646c08cebd24bcdc5247
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/bbb80f004f7a90c3dcaacc982c59967457254a05
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c84f6ce918a9e6f4996597cbc62536bbf2247c96
    Patch