Wind River Support Network

HomeDefectsLIN1023-12897
Acknowledged

LIN1023-12897 : Security Advisory - linux - CVE-2025-37812

Created: May 9, 2025    Updated: May 13, 2025
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: cdns3: Fix deadlock when using NCM gadget\n\nThe cdns3 driver has the same NCM deadlock as fixed in cdnsp by commit\n58f2fcb3a845 ("usb: cdnsp: Fix deadlock issue during using NCM gadget").\n\nUnder PREEMPT_RT the deadlock can be readily triggered by heavy network\ntraffic, for example using "iperf --bidir" over NCM ethernet link.\n\nThe deadlock occurs because the threaded interrupt handler gets\npreempted by a softirq, but both are protected by the same spinlock.\nPrevent deadlock by disabling softirq during threaded irq handler.\n']
CREATE(Triage):(User=admin) [CVE-2025-37812 (https://nvd.nist.gov/vuln/detail/CVE-2025-37812)
Live chat
Online