
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-37864 is a vulnerability discovered in the Linux kernel related to the cleanup of FDB (Forwarding Database), MDB (Multicast Database), and VLAN entries during DSA (Distributed Switch Architecture) unbinding operations. The vulnerability was disclosed on May 9, 2025, and affects the networking subsystem of the Linux kernel (NVD CVE, Wiz Security).
The vulnerability stems from the assumption in DSA that higher layers maintain balanced additions and deletions of entries. When these assumptions are violated during driver unbinding, it can lead to lingering entries and potential issues. The issue specifically affects the handling of bridge bypass operations and VLAN entry cleanup in the DSA subsystem. The vulnerability has been assigned a CVSS v3.1 Base Score of 5.5 (Moderate severity) (Red Hat Security).
The vulnerability can result in improper cleanup of FDB (Forwarding Database), MDB (Multicast Database), and VLAN entries when a DSA driver unbinds, potentially leading to resource leaks and system instability (NVD CVE).
The vulnerability has been resolved in the Linux kernel through patches that implement proper cleanup of FDB, MDB, and VLAN entries during unbinding operations. The fix includes adding informational prints to the kernel log to help identify potential issues (NVD CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."