Wind River Support Network

HomeDefectsLIN1024-9515
Fixed

LIN1024-9515 : Security Advisory - linux - CVE-2025-37997

Created: May 30, 2025    Updated: Jun 8, 2025
Resolved Date: Jun 5, 2025
Found In Version: 10.24.33.1
Fix Version: 10.24.33.10
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ipset: fix region locking in hash types

Region locking introduced in v5.6-rc4 contained three macros to handle
the region locks: ahash_bucket_start(), ahash_bucket_end() which gave
back the start and end hash bucket values belonging to a given region
lock and ahash_region() which should give back the region lock belonging
to a given hash bucket. The latter was incorrect which can lead to a
race condition between the garbage collector and adding new elements
when a hash type of set is defined with timeouts.

CREATE(Triage):(User=admin) CVE-2025-37997 (https://nvd.nist.gov/vuln/detail/CVE-2025-37997)

CVEs


Live chat
Online