CVE-2025-37879

HIGH EPSS 13.8%
Published May 9, 20251y ago · Modified Jun 17, 20262w ago
7.1 CVSS 3.1
High
Find Similar
Published May 9, 2025 1y ago
Last Modified Jun 17, 2026 2w ago

Description

In the Linux kernel, the following vulnerability has been resolved: 9p/net: fix improper handling of bogus negative read/write replies In p9_client_write() and p9_client_read_once(), if the server incorrectly replies with success but a negative write/read count then we would consider written (negative) <= rsize (positive) because both variables were signed. Make variables unsigned to avoid this problem. The reproducer linked below now fails with the following error instead of a null pointer deref: 9pnet: bogus RWRITE count (4294967295 > 3)

CVSS Details

Base Score
7.1
Exploitability
1.8
Impact
5.2
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
13.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-125 Out-of-bounds Read Memory Safety

Affected Products 5

VendorProductVersionRange
linuxlinux_kernel* <6.1.136
linuxlinux_kernel*≥6.2  –  <6.6.89
linuxlinux_kernel*≥6.7  –  <6.12.26
linuxlinux_kernel*≥6.13  –  <6.14.5
debiandebian_linux11.0any

References 6

  • git.kernel.org https://git.kernel.org/stable/c/374e4cd75617c8c2552f562f39dd989583f5c330
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/468ff4a7c61fb811c596a7c44b6a5455e40fd12b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a68768e280b7d0c967ea509e791bb9b90adc94a5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c548f95688e2b5ae0e2ae43d53cf717156c7d034
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d0259a856afca31d699b706ed5e2adf11086c73b
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/05/msg00045.html
    Mailing ListThird Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/374e4cd75617c8c2552f562f39dd989583f5c330
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/468ff4a7c61fb811c596a7c44b6a5455e40fd12b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a68768e280b7d0c967ea509e791bb9b90adc94a5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/c548f95688e2b5ae0e2ae43d53cf717156c7d034
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d0259a856afca31d699b706ed5e2adf11086c73b
    Patch