CVE-2025-37939
Linux Ubuntu vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2025-37939) was identified in the Linux kernel's libbpf component, specifically in the btf_ext_parse_info() function. The vulnerability was discovered and reported by the OSS Fuzz project and disclosed on May 20, 2025. The issue affects the BTF.ext core_relo header processing in the Linux kernel (NVD, Wiz).

Technical details

The vulnerability exists in the btf_ext_parse_info() function where it fails to properly validate the presence of the core_relo header before attempting to read its fields. This oversight can lead to a potential buffer read overflow condition. According to Red Hat's assessment, the vulnerability has been assigned a CVSS 3.1 base score of 5.5 with the vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H (Red Hat).

Impact

The vulnerability could potentially lead to a buffer read overflow, which might allow attackers to access memory contents beyond the intended boundaries. This could result in information disclosure or system instability (Wiz).

Mitigation and workarounds

The vulnerability has been resolved in the Linux kernel through a patch that updates the btf_ext_parse_info() function to properly verify the presence of the core_relo header before accessing its fields (NVD).

Additional resources


SourceThis report was generated using AI

Related Linux Ubuntu vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-21441HIGH8.9
  • PythonPython
  • barman
NoYesJan 07, 2026
CVE-2025-68766HIGH7.1
  • Linux DebianLinux Debian
  • linux-gcp-fips
NoYesJan 05, 2026
CVE-2025-68765MEDIUM5.5
  • Linux DebianLinux Debian
  • linux-lowlatency
NoYesJan 05, 2026
CVE-2025-68764MEDIUM5.5
  • Linux KernelLinux Kernel
  • linux-realtime
NoYesJan 05, 2026
CVE-2025-68763MEDIUM5.5
  • Linux DebianLinux Debian
  • linux-gcp
NoYesJan 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management