CVE-2025-37773
In the Linux kernel, the following vulnerability has been resolved: virtiofs: add filesystem context source name check In certain scenarios, for example, during fuzz testing, the source name may be NULL, which could lead to a kernel panic.
Does this matter?
Lower severity and a low EPSS score (0.19%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: virtiofs: add filesystem context source name check In certain scenarios, for example, during fuzz testing, the source name may be NULL, which could lead to a kernel panic. Therefore, an extra check for the source name should be added.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.19% probability · 9th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel · debian/debian linux
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/599d1e2a6aecc44acf22fe7ea6f5e84a7e526abePatch
- https://git.kernel.org/stable/c/5ee09cdaf3414f6c92960714af46d3d90eede2f3Patch
- https://git.kernel.org/stable/c/9d6dcf18a1b49990295ac8a05fd9bdfd27ccbf88Patch
- https://git.kernel.org/stable/c/a648d80f8d9b208beee03a2d9aa690cfacf1d41ePatch
- https://git.kernel.org/stable/c/a94fd938df2b1628da66b498aa0eeb89593bc7a2Patch
- https://git.kernel.org/stable/c/b84f13fdad10a543e2e65bab7e81b3f0bceabd67Patch
- https://git.kernel.org/stable/c/c3e31d613951c299487844c4d1686a933e8ee291Patch
- https://git.kernel.org/stable/c/f6ec52710dc5e156b774cbef5d0f5c99b1c53a80Patch
- https://lists.debian.org/debian-lts-announce/2025/05/msg00030.htmlMailing List
- https://lists.debian.org/debian-lts-announce/2025/05/msg00045.htmlMailing List
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.