« Volver al listado

CVE-2025-37997

Estado: ModificadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ipset: fix region locking in hash types

Region locking introduced in v5.6-rc4 contained three macros to handle the region locks: ahash_bucket_start(), ahash_bucket_end() which gave back the start and end hash bucket values belonging to a given region lock and ahash_region() which should give back the region lock belonging to a given hash bucket. The latter was incorrect which can lead to a race condition between the garbage collector and adding new elements when a hash type of set is defined with timeouts.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-37997",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5dd9488ae41070b69d2f4acb580f77db5705f9ca",
              "lessThan": "00cfc5fad1491796942a948808afb968a0a3f35b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f66ee0410b1c3481ee75e5db9b34547b4d582465",
              "lessThan": "226ce0ec38316d9e3739e73a64b6b8304646c658",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f66ee0410b1c3481ee75e5db9b34547b4d582465",
              "lessThan": "82c1eb32693bc48251d92532975e19160987e5b9",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f66ee0410b1c3481ee75e5db9b34547b4d582465",
              "lessThan": "aa77294b0f73bb8265987591460cd25b8722c3df",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f66ee0410b1c3481ee75e5db9b34547b4d582465",
              "lessThan": "a3dfec485401943e315c394c29afe2db8f9481d6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f66ee0410b1c3481ee75e5db9b34547b4d582465",
              "lessThan": "e2ab67672b2288521a6146034a971f9a82ffc5c5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f66ee0410b1c3481ee75e5db9b34547b4d582465",
              "lessThan": "6e002ecc1c8cfdfc866b9104ab7888da54613e59",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f66ee0410b1c3481ee75e5db9b34547b4d582465",
              "lessThan": "8478a729c0462273188263136880480729e9efca",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "a469bab3386aebff33c59506f3a95e35b91118fd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5.4.24",
              "lessThan": "5.4.294",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.5.8",
              "lessThan": "5.6",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "net/netfilter/ipset/ip_set_hash_gen.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.6"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.6",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.4.294",
              "versionType": "semver",
              "lessThanOrEqual": "5.4.*"
            },
            {
              "status": "unaffected",
              "version": "5.10.238",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.183",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.139",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.91",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.29",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.14.7",
              "versionType": "semver",
              "lessThanOrEqual": "6.14.*"
            },
            {
              "status": "unaffected",
              "version": "6.15",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "net/netfilter/ipset/ip_set_hash_gen.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-05-29T14:15:36.317",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/00cfc5fad1491796942a948808afb968a0a3f35b",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/226ce0ec38316d9e3739e73a64b6b8304646c658",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/6e002ecc1c8cfdfc866b9104ab7888da54613e59",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/82c1eb32693bc48251d92532975e19160987e5b9",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8478a729c0462273188263136880480729e9efca",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a3dfec485401943e315c394c29afe2db8f9481d6",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/aa77294b0f73bb8265987591460cd25b8722c3df",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/e2ab67672b2288521a6146034a971f9a82ffc5c5",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2025/08/msg00010.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2025/10/msg00007.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-667"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ipset: fix region locking in hash types\n\nRegion locking introduced in v5.6-rc4 contained three macros to handle\nthe region locks: ahash_bucket_start(), ahash_bucket_end() which gave\nback the start and end hash bucket values belonging to a given region\nlock and ahash_region() which should give back the region lock belonging\nto a given hash bucket. The latter was incorrect which can lead to a\nrace condition between the garbage collector and adding new elements\nwhen a hash type of set is defined with timeouts."
    },
    {
      "lang": "es",
      "value": "En el kernel de Linux, se ha resuelto la siguiente vulnerabilidad: netfilter: ipset: corrección del bloqueo de región en tipos hash. El bloqueo de región introducido en la versión v5.6-rc4 contenía tres macros para gestionar los bloqueos de región: ahash_bucket_start(), ahash_bucket_end(), que devolvía los valores de inicio y fin del depósito hash correspondientes a un bloqueo de región determinado, y ahash_region(), que debería devolver el bloqueo de región correspondiente a un depósito hash determinado. Esta última era incorrecta, lo que puede generar una condición de ejecución entre el recolector de elementos no utilizados y la adición de nuevos elementos cuando se define un tipo hash de conjunto con tiempos de espera."
    }
  ],
  "lastModified": "2026-07-30T06:22:43.087",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FB89D6F8-FCFA-4003-8BAF-21EAA9437EEC",
              "versionEndExcluding": "5.4.294",
              "versionStartIncluding": "5.4.24"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3C9E794-4183-4A8B-8E8E-FBBD9B334429",
              "versionEndExcluding": "5.6",
              "versionStartIncluding": "5.5.8"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0C9C873-9D1C-4943-9A1F-755B15F4C242",
              "versionEndExcluding": "5.10.238",
              "versionStartIncluding": "5.6.1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "94D91ED4-346E-41EE-ACF5-F184C0A863D5",
              "versionEndExcluding": "5.15.183",
              "versionStartIncluding": "5.11"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "70A2F216-574B-4B80-86BC-988928D5B83D",
              "versionEndExcluding": "6.1.139",
              "versionStartIncluding": "5.16"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B6826C73-C5C9-430D-84C9-4045DFD72074",
              "versionEndExcluding": "6.6.91",
              "versionStartIncluding": "6.2"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7215ABCF-8EB1-46CD-8872-8BCE4890E579",
              "versionEndExcluding": "6.12.29",
              "versionStartIncluding": "6.7"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5715A6F5-A34A-4B27-8A64-82825E963995",
              "versionEndExcluding": "6.14.7",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:5.6:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A92F7A0E-C302-4FEA-9EF3-1A3D5CF3AD54"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:5.6:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DC0C894E-6323-44E5-89DD-8FB6A5C41CAF"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:5.6:rc5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C76EAC9-C2E6-4B6F-B002-ADBE74DDD794"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:5.6:rc6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F13B8FBF-E007-4F60-A290-2833B45F8520"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:5.6:rc7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CD0276C4-2C60-4C52-AC89-F96DF991B858"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D465631-2980-487A-8E65-40AE2B9F8ED1"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C9D071F-B28E-46EC-AC61-22B913390211"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "13FC0DDE-E513-465E-9E81-515702D49B74"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C7B5B0E-4EEB-48F5-B4CF-0935A7633845"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:6.15:rc5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D240580-3048-49B2-9E27-F115A9DF8224"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA6FEEC2-9F11-4643-8827-749718254FED"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}