CVE-2025-37966
MEDIUM EPSS 3.0%
Published May 20, 20251y ago · Modified Jun 17, 20262w ago
5.5 CVSS 3.1
Published May 20, 2025 1y ago
Last Modified Jun 17, 2026 2w ago
Description
In the Linux kernel, the following vulnerability has been resolved: riscv: Fix kernel crash due to PR_SET_TAGGED_ADDR_CTRL When userspace does PR_SET_TAGGED_ADDR_CTRL, but Supm extension is not available, the kernel crashes: Oops - illegal instruction [#1] [snip] epc : set_tagged_addr_ctrl+0x112/0x15a ra : set_tagged_addr_ctrl+0x74/0x15a epc : ffffffff80011ace ra : ffffffff80011a30 sp : ffffffc60039be10 [snip] status: 0000000200000120 badaddr: 0000000010a79073 cause: 0000000000000002 set_tagged_addr_ctrl+0x112/0x15a __riscv_sys_prctl+0x352/0x73c do_trap_ecall_u+0x17c/0x20c andle_exception+0x150/0x15c Fix it by checking if Supm is available.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High
Threat Intelligence
EPSS Exploit Probability
3.0% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Affected Products 6
References 2
- git.kernel.org https://git.kernel.org/stable/c/4b595a2f5656cd45d534ed2160c94f7662adefe5
- git.kernel.org https://git.kernel.org/stable/c/ae08d55807c099357c047dba17624b09414635dd
Remediation
- git.kernel.org https://git.kernel.org/stable/c/4b595a2f5656cd45d534ed2160c94f7662adefe5
- git.kernel.org https://git.kernel.org/stable/c/ae08d55807c099357c047dba17624b09414635dd