AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-37886

HIGH · CVSS 7.8 EPSS 0.26%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-05-09 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.8. It affects Linux.

CVE
CVE-2025-37886
Severity
HIGH
CVSS
7.8
EPSS
0.26%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: pds_core: make wait_context part of q_info Make the wait_context a full part of the q_info struct rather than a stack variable that goes away after pdsc_adminq_post() is done so that the context is still available after the wait loop has given up. There was a case where a slow development firmware caused the adminq request to time out, but then later the FW finally finished the request and sent the interrupt. The handler tried to complete_all() the completion context that had been created on the stack in pdsc_adminq_post() but no longer existed. This caused bad pointer usage, kernel crashes, and much wailing and gnashing of teeth.

Related CVEs

Other vulnerabilities affecting the same vendor(s)