Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2025-37887

7.1 · HIGH
Published May 9, 2025 linux CWE-908 EPSS 0.27% (19th pctl)

Overview

CVE-2025-37887 is a high-severity vulnerability affecting linux linux_kernel. It was published on May 9, 2025 and has a CVSS 3.1 base score of 7.1 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.1, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

pds_core: handle unsupported PDS_CORE_CMD_FW_CONTROL result

If the FW doesn't support the PDS_CORE_CMD_FW_CONTROL command

the driver might at the least print garbage and at the worst

crash when the user runs the "devlink dev info" devlink command.

This happens because the stack variable fw_list is not 0

initialized which results in fw_list.num_fw_slots being a

garbage value from the stack. Then the driver tries to access

fw_list.fw_names[i] with i >= ARRAY_SIZE and runs off the end

of the array.

Fix this by initializing the fw_list and by not failing

completely if the devcmd fails because other useful information

is printed via devlink dev info even if the devcmd fails.

Remediation

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
linux linux_kernel >= 6.4, < 6.6.89 Affected

Frequently Asked Questions

What is CVE-2025-37887?

CVE-2025-37887 is a high-severity vulnerability affecting linux linux_kernel. It was published on May 9, 2025 and has a CVSS 3.1 base score of 7.1 (HIGH).

How severe is CVE-2025-37887?

This vulnerability has a CVSS 3.1 base score of 7.1, rated HIGH. It requires local or adjacent network access to exploit. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2025-37887?

Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2025-37887?

CyberStrike's AI-powered security agents can automatically detect CVE-2025-37887 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.