CVE-2025-37813

Analyzed
Published: 08 May 2025, 06:26
Last modified:23 May 2026, 15:58

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.07% LOW
0% probability +0.04%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

08 May 2025, 06:26
Published
Vulnerability first disclosed
23 May 2026, 15:58
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Fix invalid pointer dereference in Etron workaround This check is performed before prepare_transfer() and prepare_ring(), so enqueue can already point at the final link TRB of a segment. And indeed it will, some 0.4% of times this code is called. Then enqueue + 1 is an invalid pointer. It will crash the kernel right away or load some junk which may look like a link TRB and cause the real link TRB to be replaced with a NOOP. This wouldn't end well. Use a functionally equivalent test which doesn't dereference the pointer and always gives correct result. Something has crashed my machine twice in recent days while playing with an Etron HC, and a control transfer stress test ran for confirmation has just crashed it again. The same test passes with this patch applied.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.07% Percentile: 20%

Techniques & Countermeasures

  • CWE-476NULL Pointer Dereference

    The product dereferences a pointer that it expects to be valid but is NULL.

Affected Systems

  • linuxlinux

    ≥ fbc0a0c7718a6cb1dc5e0811a4f88a2b1deedfa1, < 142273a49f2c315eabdbdf5a71c15e479b75ca91 | ≥ 9258c9ed32294ce3a4b58c9d92fc49ba030d35c9, < bce3055b08e303e28a8751f6073066f5c33a0744 | ≥ 5e1c67abc9301d05130b7e267c204e7005503b33, < 0624e29c595b05e7a0e6d1c368f0a05799928e30 | ≥ 5e1c67abc9301d05130b7e267c204e7005503b33, < 1ea050da5562af9b930d17cbbe9632d30f5df43a | 4725344ca645a98a9d8e45e25b01a2244de5b8aa | ≥ 6.6.66, < 6.6.89 | ≥ 6.12.2, < 6.12.26 | ≥ 6.11.11, < 6.12 | 6.13

  • linuxlinux_kernel

    ≥ 6.6.66, < 6.6.89 | ≥ 6.11.11, < 6.12 | ≥ 6.12.2, < 6.12.26 | ≥ 6.13, < 6.14.5 | 6.15:rc1 | 6.15:rc2 | 6.15:rc3

References (4)