CVE-2025-37875

MEDIUM EPSS 13.1%
Published May 9, 20251y ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 9, 2025 1y ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: igc: fix PTM cycle trigger logic Writing to clear the PTM status 'valid' bit while the PTM cycle is triggered results in unreliable PTM operation. To fix this, clear the PTM 'trigger' and status after each PTM transaction. The issue can be reproduced with the following: $ sudo phc2sys -R 1000 -O 0 -i tsn0 -m Note: 1000 Hz (-R 1000) is unrealistically large, but provides a way to quickly reproduce the issue. PHC2SYS exits with: "ioctl PTP_OFFSET_PRECISE: Connection timed out" when the PTM transaction fails This patch also fixes a hang in igc_probe() when loading the igc driver in the kdump kernel on systems supporting PTM. The igc driver running in the base kernel enables PTM trigger in igc_probe(). Therefore the driver is always in PTM trigger mode, except in brief periods when manually triggering a PTM cycle. When a crash occurs, the NIC is reset while PTM trigger is enabled. Due to a hardware problem, the NIC is subsequently in a bad busmaster state and doesn't handle register reads/writes. When running igc_probe() in the kdump kernel, the first register access to a NIC register hangs driver probing and ultimately breaks kdump. With this patch, igc has PTM trigger disabled most of the time, and the trigger is only enabled for very brief (10 - 100 us) periods when manually triggering a PTM cycle. Chances that a crash occurs during a PTM trigger are not 0, but extremely reduced.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
13.1% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 8

VendorProductVersionRange
linuxlinux_kernel*≥5.15  –  <5.15.181
linuxlinux_kernel*≥5.16  –  <6.1.135
linuxlinux_kernel*≥6.2  –  <6.6.88
linuxlinux_kernel*≥6.7  –  <6.12.25
linuxlinux_kernel*≥6.13  –  <6.14.4
linuxlinux_kernel6.15any
linuxlinux_kernel6.15any
debiandebian_linux11.0any

References 7

  • git.kernel.org https://git.kernel.org/stable/c/0c03e4fbe1321697d9d04587e21e416705e1b19f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/16194ca3f3b4448a062650c869a7b3b206c6f5d3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/31959e06143692f7e02b8eef7d7d6ac645637906
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8e404ad95d2c10c261e2ef6992c7c12dde03df0e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c1f174edaccc5a00f8e218c42a0aa9156efd5f76
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f3516229cd12dcd45f23ed01adab17e8772b1bd5
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
    Mailing ListThird Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/0c03e4fbe1321697d9d04587e21e416705e1b19f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/16194ca3f3b4448a062650c869a7b3b206c6f5d3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/31959e06143692f7e02b8eef7d7d6ac645637906
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/8e404ad95d2c10c261e2ef6992c7c12dde03df0e
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c1f174edaccc5a00f8e218c42a0aa9156efd5f76
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f3516229cd12dcd45f23ed01adab17e8772b1bd5
    Patch