[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2025-37761":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-04T08:53:30.047Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":23,"aliases":24,"duplicate_of":9,"upstream":25,"downstream":26,"duplicates":79,"related":80,"reserved_at":9,"published_at":84,"modified_at":85,"state":86,"summary":87,"references_raw":96,"kevs":111,"epss":112,"epss_history":115,"metrics":384,"affected":390},"CVE-2025-37761","In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/xe: Fix an out-of-bounds shift when invalidating TLB\n\nWhen the size of the range invalidated is larger than\nrounddown_pow_of_two(ULONG_MAX),\nThe function macro roundup_pow_of_two(length) will hit an out-of-bounds\nshift [1].\n\nUse a full TLB invalidation for such cases.\nv2:\n- Use a define for the range size limit over which we use a full\n  TLB invalidation. (Lucas)\n- Use a better calculation of the limit.\n\n[1]:\n[   39.202421] ------------[ cut here ]------------\n[   39.202657] UBSAN: shift-out-of-bounds in ./include/linux/log2.h:57:13\n[   39.202673] shift exponent 64 is too large for 64-bit type 'long unsigned int'\n[   39.202688] CPU: 8 UID: 0 PID: 3129 Comm: xe_exec_system_ Tainted: G     U             6.14.0+ #10\n[   39.202690] Tainted: [U]=USER\n[   39.202690] Hardware name: ASUS System Product Name/PRIME B560M-A AC, BIOS 2001 02/01/2023\n[   39.202691] Call Trace:\n[   39.202692]  \u003CTASK>\n[   39.202695]  dump_stack_lvl+0x6e/0xa0\n[   39.202699]  ubsan_epilogue+0x5/0x30\n[   39.202701]  __ubsan_handle_shift_out_of_bounds.cold+0x61/0xe6\n[   39.202705]  xe_gt_tlb_invalidation_range.cold+0x1d/0x3a [xe]\n[   39.202800]  ? find_held_lock+0x2b/0x80\n[   39.202803]  ? mark_held_locks+0x40/0x70\n[   39.202806]  xe_svm_invalidate+0x459/0x700 [xe]\n[   39.202897]  drm_gpusvm_notifier_invalidate+0x4d/0x70 [drm_gpusvm]\n[   39.202900]  __mmu_notifier_release+0x1f5/0x270\n[   39.202905]  exit_mmap+0x40e/0x450\n[   39.202912]  __mmput+0x45/0x110\n[   39.202914]  exit_mm+0xc5/0x130\n[   39.202916]  do_exit+0x21c/0x500\n[   39.202918]  ? lockdep_hardirqs_on_prepare+0xdb/0x190\n[   39.202920]  do_group_exit+0x36/0xa0\n[   39.202922]  get_signal+0x8f8/0x900\n[   39.202926]  arch_do_signal_or_restart+0x35/0x100\n[   39.202930]  syscall_exit_to_user_mode+0x1fc/0x290\n[   39.202932]  do_syscall_64+0xa1/0x180\n[   39.202934]  ? do_user_addr_fault+0x59f/0x8a0\n[   39.202937]  ? lock_release+0xd2/0x2a0\n[   39.202939]  ? do_user_addr_fault+0x5a9/0x8a0\n[   39.202942]  ? trace_hardirqs_off+0x4b/0xc0\n[   39.202944]  ? clear_bhb_loop+0x25/0x80\n[   39.202946]  ? clear_bhb_loop+0x25/0x80\n[   39.202947]  ? clear_bhb_loop+0x25/0x80\n[   39.202950]  entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[   39.202952] RIP: 0033:0x7fa945e543e1\n[   39.202961] Code: Unable to access opcode bytes at 0x7fa945e543b7.\n[   39.202962] RSP: 002b:00007ffca8fb4170 EFLAGS: 00000293\n[   39.202963] RAX: 000000000000003d RBX: 0000000000000000 RCX: 00007fa945e543e3\n[   39.202964] RDX: 0000000000000000 RSI: 00007ffca8fb41ac RDI: 00000000ffffffff\n[   39.202964] RBP: 00007ffca8fb4190 R08: 0000000000000000 R09: 00007fa945f600a0\n[   39.202965] R10: 0000000000000000 R11: 0000000000000293 R12: 0000000000000000\n[   39.202966] R13: 00007fa9460dd310 R14: 00007ffca8fb41ac R15: 0000000000000000\n[   39.202970]  \u003C/TASK>\n[   39.202970] ---[ end trace ]---\n\n(cherry picked from commit b88f48f86500bc0b44b4f73ac66d500a40d320ad)",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-125","Out-of-bounds Read","The product reads data past the end, or before the beginning, of the intended buffer.","weakness","Draft","Base",[19],{"id":20,"name":21,"techniques":22},"CAPEC-540","Overread Buffers",[],[],[],[],[27,29,31,33,35,37,39,41,43,45,47,49,51,53,55,57,59,61,63,65,67,69,71,73,75,77],{"_key":28},"USN-7594-1",{"_key":30},"USN-7594-2",{"_key":32},"USN-7594-3",{"_key":34},"RHSA-2026:1194",{"_key":36},"RHSA-2026:1236",{"_key":38},"SUSE-SU-2025:02254-1",{"_key":40},"SUSE-SU-2025:02307-1",{"_key":42},"SUSE-SU-2025:02333-1",{"_key":44},"DEBIAN-CVE-2025-37761",{"_key":46},"USN-8028-1",{"_key":48},"USN-8028-2",{"_key":50},"USN-8028-3",{"_key":52},"USN-8028-4",{"_key":54},"USN-8028-5",{"_key":56},"USN-8028-6",{"_key":58},"USN-8028-7",{"_key":60},"USN-8028-8",{"_key":62},"USN-8031-1",{"_key":64},"USN-8031-2",{"_key":66},"USN-8031-3",{"_key":68},"USN-8052-1",{"_key":70},"USN-8052-2",{"_key":72},"USN-8074-1",{"_key":74},"USN-8074-2",{"_key":76},"USN-8126-1",{"_key":78},"UBUNTU-CVE-2025-37761",[],[81,82,83],{"_key":38},{"_key":40},{"_key":42},"2025-05-01T13:07:03.389Z","2026-05-11T21:14:38.137Z","Analyzed",{"cisa_kev":88,"cisa_ransomware":88,"cisa_vendor":9,"epss_severity":89,"epss_score":90,"severity":91,"severity_score":92,"severity_version":93,"severity_source":94,"severity_vector":95,"severity_status":86},false,"low",0.00052,"high",7.1,"v3.1","nvd","CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",[97,103,107],{"url":98,"sources":99,"tags":101},"https://git.kernel.org/stable/c/28477f701b63922ff88e9fb13f5519c11cd48b86",[100,94],"cve.org",[102],"Patch",{"url":104,"sources":105,"tags":106},"https://git.kernel.org/stable/c/e4715858f87b78ce58cfa03bbe140321edbbaf20",[100,94],[102],{"url":108,"sources":109,"tags":110},"https://git.kernel.org/stable/c/7bcfeddb36b77f9fe3b010bb0b282b7618420bba",[100,94],[102],[],{"date":113,"score":90,"percentile":114},"2026-06-03",0.16474,[116,120,123,126,130,133,136,139,141,144,147,150,153,156,159,163,166,169,172,175,178,181,185,188,191,194,197,200,203,206,209,212,215,218,220,222,225,228,231,234,237,240,242,245,248,250,253,255,258,261,263,266,269,272,275,278,281,284,287,290,293,296,299,302,305,308,311,314,317,320,322,325,327,331,334,337,340,343,346,349,352,355,358,362,365,369,372,375,378,381],{"date":117,"score":118,"percentile":119},"2025-11-04",0.00024,0.05027,{"date":121,"score":118,"percentile":122},"2025-11-05",0.05029,{"date":124,"score":118,"percentile":125},"2025-11-06",0.05144,{"date":127,"score":128,"percentile":129},"2025-11-07",0.00012,0.01318,{"date":131,"score":128,"percentile":132},"2025-11-08",0.01322,{"date":134,"score":128,"percentile":135},"2025-11-09",0.01319,{"date":137,"score":128,"percentile":138},"2025-11-10",0.01306,{"date":140,"score":128,"percentile":129},"2025-11-11",{"date":142,"score":128,"percentile":143},"2025-11-12",0.0132,{"date":145,"score":128,"percentile":146},"2025-11-13",0.01334,{"date":148,"score":128,"percentile":149},"2025-11-14",0.01349,{"date":151,"score":128,"percentile":152},"2025-11-15",0.01369,{"date":154,"score":128,"percentile":155},"2025-11-16",0.01368,{"date":157,"score":128,"percentile":158},"2025-11-17",0.01358,{"date":160,"score":161,"percentile":162},"2025-11-18",0.00026,0.03549,{"date":164,"score":161,"percentile":165},"2025-11-19",0.03599,{"date":167,"score":161,"percentile":168},"2025-11-20",0.03667,{"date":170,"score":128,"percentile":171},"2025-11-21",0.01415,{"date":173,"score":128,"percentile":174},"2025-11-22",0.01414,{"date":176,"score":128,"percentile":177},"2025-11-23",0.01401,{"date":179,"score":128,"percentile":180},"2025-11-24",0.01393,{"date":182,"score":183,"percentile":184},"2025-11-25",0.00014,0.01827,{"date":186,"score":183,"percentile":187},"2025-11-26",0.01789,{"date":189,"score":183,"percentile":190},"2025-11-27",0.01788,{"date":192,"score":183,"percentile":193},"2025-11-28",0.01785,{"date":195,"score":183,"percentile":196},"2025-11-29",0.01832,{"date":198,"score":183,"percentile":199},"2025-11-30",0.0184,{"date":201,"score":183,"percentile":202},"2025-12-01",0.01874,{"date":204,"score":183,"percentile":205},"2025-12-02",0.01872,{"date":207,"score":183,"percentile":208},"2025-12-03",0.01878,{"date":210,"score":183,"percentile":211},"2025-12-04",0.01843,{"date":213,"score":183,"percentile":214},"2025-12-05",0.0186,{"date":216,"score":183,"percentile":217},"2025-12-06",0.01864,{"date":219,"score":183,"percentile":214},"2025-12-07",{"date":221,"score":183,"percentile":214},"2025-12-08",{"date":223,"score":183,"percentile":224},"2025-12-09",0.01877,{"date":226,"score":183,"percentile":227},"2025-12-10",0.01904,{"date":229,"score":183,"percentile":230},"2025-12-11",0.01895,{"date":232,"score":183,"percentile":233},"2025-12-12",0.01901,{"date":235,"score":183,"percentile":236},"2025-12-13",0.01884,{"date":238,"score":183,"percentile":239},"2025-12-14",0.01886,{"date":241,"score":183,"percentile":208},"2025-12-15",{"date":243,"score":183,"percentile":244},"2025-12-16",0.01873,{"date":246,"score":183,"percentile":247},"2025-12-17",0.01889,{"date":249,"score":183,"percentile":239},"2025-12-18",{"date":251,"score":183,"percentile":252},"2025-12-19",0.01887,{"date":254,"score":183,"percentile":252},"2025-12-20",{"date":256,"score":183,"percentile":257},"2025-12-21",0.01897,{"date":259,"score":183,"percentile":260},"2025-12-22",0.01896,{"date":262,"score":183,"percentile":257},"2025-12-23",{"date":264,"score":183,"percentile":265},"2025-12-24",0.01905,{"date":267,"score":183,"percentile":268},"2025-12-25",0.0191,{"date":270,"score":183,"percentile":271},"2025-12-26",0.01911,{"date":273,"score":183,"percentile":274},"2025-12-27",0.0189,{"date":276,"score":183,"percentile":277},"2025-12-28",0.01909,{"date":279,"score":183,"percentile":280},"2025-12-29",0.019,{"date":282,"score":183,"percentile":283},"2025-12-30",0.01893,{"date":285,"score":183,"percentile":286},"2025-12-31",0.01891,{"date":288,"score":183,"percentile":289},"2026-01-01",0.01915,{"date":291,"score":183,"percentile":292},"2026-01-02",0.01907,{"date":294,"score":183,"percentile":295},"2026-01-03",0.01912,{"date":297,"score":183,"percentile":298},"2026-01-04",0.01991,{"date":300,"score":183,"percentile":301},"2026-01-05",0.01998,{"date":303,"score":183,"percentile":304},"2026-01-06",0.01994,{"date":306,"score":183,"percentile":307},"2026-01-07",0.02012,{"date":309,"score":183,"percentile":310},"2026-01-08",0.0203,{"date":312,"score":183,"percentile":313},"2026-01-09",0.02046,{"date":315,"score":183,"percentile":316},"2026-01-10",0.0206,{"date":318,"score":183,"percentile":319},"2026-01-11",0.02048,{"date":321,"score":183,"percentile":319},"2026-01-12",{"date":323,"score":183,"percentile":324},"2026-01-13",0.02038,{"date":326,"score":183,"percentile":313},"2026-01-14",{"date":328,"score":329,"percentile":330},"2026-01-15",0.00017,0.03422,{"date":332,"score":329,"percentile":333},"2026-01-16",0.03414,{"date":335,"score":329,"percentile":336},"2026-01-17",0.03416,{"date":338,"score":329,"percentile":339},"2026-01-18",0.03405,{"date":341,"score":329,"percentile":342},"2026-01-19",0.03386,{"date":344,"score":329,"percentile":345},"2026-01-20",0.03377,{"date":347,"score":329,"percentile":348},"2026-01-21",0.03363,{"date":350,"score":329,"percentile":351},"2026-01-22",0.03365,{"date":353,"score":329,"percentile":354},"2026-01-23",0.0341,{"date":356,"score":329,"percentile":357},"2026-01-24",0.03437,{"date":359,"score":360,"percentile":361},"2026-01-25",0.00019,0.04226,{"date":363,"score":360,"percentile":364},"2026-01-26",0.04216,{"date":366,"score":367,"percentile":368},"2026-01-27",0.0002,0.0443,{"date":370,"score":367,"percentile":371},"2026-01-28",0.04415,{"date":373,"score":367,"percentile":374},"2026-01-29",0.04432,{"date":376,"score":360,"percentile":377},"2026-01-30",0.04207,{"date":379,"score":360,"percentile":380},"2026-01-31",0.04183,{"date":382,"score":360,"percentile":383},"2026-02-01",0.04288,[385],{"source":94,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":386,"cvss_v4_0":9},{"baseScore":92,"baseSeverity":387,"vectorString":95,"impactScore":388,"exploitabilityScore":389},"HIGH",8.7,4.6,[391,411],{"ecosystem":9,"name":392,"vendor":393,"product":393,"cpe_part":394,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":395},"Linux","linux","a",[396,403,406,409],{"version":397,"is_range":398,"range_type":100,"version_start":399,"version_start_type":400,"version_end":401,"version_end_type":402,"fixed_in":9},">= 332dd0116c82a75df175a459fa69dda3f23491a7, \u003C 28477f701b63922ff88e9fb13f5519c11cd48b86",true,"332dd0116c82a75df175a459fa69dda3f23491a7","including","28477f701b63922ff88e9fb13f5519c11cd48b86","excluding",{"version":404,"is_range":398,"range_type":100,"version_start":399,"version_start_type":400,"version_end":405,"version_end_type":402,"fixed_in":9},">= 332dd0116c82a75df175a459fa69dda3f23491a7, \u003C e4715858f87b78ce58cfa03bbe140321edbbaf20","e4715858f87b78ce58cfa03bbe140321edbbaf20",{"version":407,"is_range":398,"range_type":100,"version_start":399,"version_start_type":400,"version_end":408,"version_end_type":402,"fixed_in":9},">= 332dd0116c82a75df175a459fa69dda3f23491a7, \u003C 7bcfeddb36b77f9fe3b010bb0b282b7618420bba","7bcfeddb36b77f9fe3b010bb0b282b7618420bba",{"version":410,"is_range":88,"range_type":100,"version_start":410,"version_start_type":400,"version_end":410,"version_end_type":400,"fixed_in":9},"6.8",{"ecosystem":9,"name":412,"vendor":393,"product":413,"cpe_part":414,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":415},"linux kernel","linux_kernel","o",[416,420,424],{"version":417,"is_range":398,"range_type":418,"version_start":410,"version_start_type":400,"version_end":419,"version_end_type":402,"fixed_in":9},"gte6.8_lt6.12.25","cpe","6.12.25",{"version":421,"is_range":398,"range_type":418,"version_start":422,"version_start_type":400,"version_end":423,"version_end_type":402,"fixed_in":9},"gte6.13_lt6.14.4","6.13","6.14.4",{"version":425,"is_range":88,"range_type":418,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"6.15:rc1"]