CVE-2025-37968

MEDIUM EPSS 2.7%
Published May 20, 20251y ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 20, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: iio: light: opt3001: fix deadlock due to concurrent flag access The threaded IRQ function in this driver is reading the flag twice: once to lock a mutex and once to unlock it. Even though the code setting the flag is designed to prevent it, there are subtle cases where the flag could be true at the mutex_lock stage and false at the mutex_unlock stage. This results in the mutex not being unlocked, resulting in a deadlock. Fix it by making the opt3001_irq() code generally more robust, reading the flag into a variable and using the variable value at both stages.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
2.7% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-667

Affected Products 13

VendorProductVersionRange
linuxlinux_kernel*≥4.3  –  <5.4.299
linuxlinux_kernel*≥5.5  –  <5.10.243
linuxlinux_kernel*≥5.11  –  <5.15.192
linuxlinux_kernel*≥5.16  –  <6.1.151
linuxlinux_kernel*≥6.2  –  <6.6.105
linuxlinux_kernel*≥6.7  –  <6.12.30
linuxlinux_kernel*≥6.13  –  <6.14.7
linuxlinux_kernel6.15any
linuxlinux_kernel6.15any
linuxlinux_kernel6.15any
linuxlinux_kernel6.15any
linuxlinux_kernel6.15any
debiandebian_linux11.0any

References 11

  • cert-portal.siemens.com https://cert-portal.siemens.com/productcert/html/ssa-032379.html
  • git.kernel.org https://git.kernel.org/stable/c/1d7def97e7eb65865ccc01bbdf4eb9e6bbe8a5b5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2c95c8f0959d0a72575eabf2ff888f47ed6d8b77
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/748ebd8e61d0bc182c331b8df3887af7285c8a8f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7ca84f6a22d50bf8b31efe9eb05f9859947266d7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/957e8be112636d9bc692917286e81e54bd87decc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a9c56ccb7cddfca754291fb24b108a5350a5fbe9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e791bf216c9e236b34dabf514ec0ede140cca719
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f063a28002e3350088b4577c5640882bf4ea17ea
    Patch
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html
    Third Party Advisory
  • lists.debian.org https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html
    Third Party Advisory

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/1d7def97e7eb65865ccc01bbdf4eb9e6bbe8a5b5
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/2c95c8f0959d0a72575eabf2ff888f47ed6d8b77
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/748ebd8e61d0bc182c331b8df3887af7285c8a8f
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/7ca84f6a22d50bf8b31efe9eb05f9859947266d7
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/957e8be112636d9bc692917286e81e54bd87decc
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/a9c56ccb7cddfca754291fb24b108a5350a5fbe9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e791bf216c9e236b34dabf514ec0ede140cca719
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/f063a28002e3350088b4577c5640882bf4ea17ea
    Patch