CVE-2025-37865
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-37865 is a vulnerability discovered in the Linux kernel, specifically affecting the net: dsa: mv88e6xxx component. The issue was publicly disclosed on May 9, 2025, and involves a bug when deleting VLANs on systems where MST (Multiple Spanning Tree) is unsupported (NVD, Debian Tracker).

Technical details

The vulnerability occurs in the mv88e6xxx_port_vlan_leave() function when it calls mv88e6xxx_mst_put(). The function attempts to find an MST entry in &chip->msts associated with the SID but fails with -ENOENT error. The root cause is that some chip->info->ops->vtu_getnext() implementations do not populate vlan.sid, leading to the use of uninitialized stack memory. The issue has been assigned a CVSS v3.1 score of 5.5 with vector AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (Red Hat).

Impact

The vulnerability affects systems using the mv88e6xxx driver for network switching, particularly when attempting to delete bridge VLANs from user ports. The impact is primarily related to system functionality, causing operations to fail with -ENOENT errors on affected devices (Debian Tracker).

Mitigation and workarounds

The issue has been fixed in various Linux kernel versions across different distributions. Debian has released fixes in version 6.1.135-1 for bookworm (security) and 6.12.25-1 for trixie. The fix involves both zero-initializing the vlan structure and adding a test for mv88e6xxx_has_stu() inside mv88e6xxx_mst_put() (Debian Tracker).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-71142N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k-core
NoNoJan 14, 2026
CVE-2025-71137N/AN/A
  • Linux KernelLinux Kernel
  • kernel-64k
NoYesJan 14, 2026
CVE-2025-71135N/AN/A
  • Linux KernelLinux Kernel
  • rv
NoNoJan 14, 2026
CVE-2025-71134N/AN/A
  • Linux KernelLinux Kernel
  • kernel-zfcpdump
NoNoJan 14, 2026
CVE-2025-71133N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-debug
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management