CVE-2025-37790

Source
https://cve.org/CVERecord?id=CVE-2025-37790
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37790.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-37790
Downstream
Related
Published
2025-05-01T13:07:23.416Z
Modified
2026-05-28T03:53:59.595605536Z
Summary
net: mctp: Set SOCK_RCU_FREE
Details

In the Linux kernel, the following vulnerability has been resolved:

net: mctp: Set SOCKRCUFREE

Bind lookup runs under RCU, so ensure that a socket doesn't go away in the middle of a lookup.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/37xxx/CVE-2025-37790.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
833ef3b91de692ef33b800bca6b1569c39dece74
Fixed
5c1313b93c8c2e3904a48aa88e2fa1db28c607ae
Fixed
b9764ebebb007249fb733a131b6110ff333b6616
Fixed
a8a3b61ce140e2b0a72a779e8d70f60c0cf1e47a
Fixed
3f899bd6dd56ddc46509b526e23a8f0a97712a6d
Fixed
e3b5edbdb45924a7d4206d13868a2aac71f1e53d
Fixed
52024cd6ec71a6ca934d0cc12452bd8d49850679

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37790.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.15.0
Fixed
5.15.181
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.135
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.88
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.25
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.14.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-37790.json"