← Back

CVE-2025-37997

nvd nist
Published: May 29, 2025Modified: Dec 16, 2025

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: fix region locking in hash types Region locking introduced in v5.6-rc4 contained three macros to handle the region locks: ahash_bucket_start(), ahash_bucket_end() which gave back the start and end hash bucket values belonging to a given region lock and ahash_region() which should give back the region lock belonging to a given hash bucket. The latter was incorrect which can lead to a race condition between the garbage collector and adding new elements when a hash type of set is defined with timeouts.

Affected (19)

1 product
Linux Kernel
1 product
Debian Linux
Configuration A
18 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 5.11 to 5.15.183
From 5.16 to 6.1.139
From 5.4.24 to 5.4.294
From 5.5.8 to 5.6
From 5.6.1 to 5.10.238
From 6.13 to 6.14.7
From 6.2 to 6.6.91
From 6.7 to 6.12.29
Version 5.6
Version 5.6 rc4
Version 5.6 rc5
Version 5.6 rc6
Version 5.6 rc7
Version 6.15 rc1
Version 6.15 rc2
Version 6.15 rc3
Version 6.15 rc4
Version 6.15 rc5
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 11.0

References (10)

Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.