Wind River Support Network

HomeDefectsLIN1023-13090
Acknowledged

LIN1023-13090 : Security Advisory - linux - CVE-2025-37963

Created: May 21, 2025    Updated: May 30, 2025
Found In Version: 10.23.30.1
Severity: Standard
Applicable for: Wind River Linux LTS 23
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

arm64: bpf: Only mitigate cBPF programs loaded by unprivileged users

Support for eBPF programs loaded by unprivileged users is typically
disabled. This means only cBPF programs need to be mitigated for BHB.

In addition, only mitigate cBPF programs that were loaded by an
unprivileged user. Privileged users can also load the same program
via eBPF, making the mitigation pointless.

CREATE(Triage):(User=admin) CVE-2025-37963 (https://nvd.nist.gov/vuln/detail/CVE-2025-37963)
Live chat
Online