
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
In the Linux kernel, CVE-2025-37810 addresses a vulnerability in the TIOCL_SELMOUSEREPORT functionality. This requirement was previously loosened in commit 2f83e38a095f but was found to have inconsistent logic and potential security risks. The vulnerability affects the tty subsystem and was discovered in early 2025 (Linux Kernel).
The vulnerability stems from inconsistent logic in handling TIOCLSELMOUSEREPORT mode parameter, where the lower four bits were used as an additional argument. The patch did still require CAPSYS_ADMIN if mouse button bits are set, but did not require it if none of the mouse buttons bits are set. This inconsistency allows potential attackers to simulate mouse movements and inject input that could be misinterpreted as keyboard input by programs like libreadline/bash (Linux Kernel).
The vulnerability can allow attackers to simulate keyboard input to command line applications on the same terminal, similar to TIOCSTI keystroke injection attacks. While attackers don't have complete control over the escape sequence, they can control values of two consecutive bytes in the binary mouse reporting escape sequence, potentially leading to unauthorized input injection (Linux Kernel).
The fix involves reverting back to requiring CAPSYSADMIN for all usages of TIOCLSELMOUSEREPORT, as it was before commit 2f83e38a095f. This is justified since TIOCLSELMOUSEREPORT is only meant to be used by mouse daemons (GPM or Consolation) which run with CAPSYSADMIN privileges already (Linux Kernel).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”