CVE-2025-37987
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-37987 is a vulnerability discovered in the Linux kernel's pdscore component, specifically related to the adminq (admin queue) handling. The vulnerability was disclosed on May 20, 2025, affecting the Linux kernel's pdscore subsystem (NVD Database).

Technical details

The vulnerability stems from a design limitation in the pdscore's adminq implementation. While the adminqlock prevents simultaneous command posting, completions occur in a different context, allowing multiple adminq commands to be posted sequentially while waiting for completion. The backing adminq request queue has a limited capacity of 16 entries, and due to insufficient retry mechanism and overflow prevention, the adminq can become stuck, resulting in commands no longer being processed and completions not being sent by the firmware (NVD Database).

Impact

When exploited, this vulnerability can cause the adminq to become stuck in a state where commands are no longer processed and completions are not sent by the firmware. This effectively creates a denial of service condition for the affected component, potentially impacting system operations that depend on the pds_core subsystem (NVD Database).

Mitigation and workarounds

A fix has been implemented that prevents more than 16 outstanding adminq commands by reducing the adminq depth to 16. This ensures that the backing adminq request queue will never have more than 16 pending adminq commands, effectively preventing overflow conditions (NVD Database).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40205HIGH7.8
  • Linux KernelLinux Kernel
  • linux-gcp-5.4
NoYesNov 12, 2025
CVE-2025-40211HIGH7.1
  • Linux KernelLinux Kernel
  • linux-gcp-6.8
NoYesNov 21, 2025
CVE-2025-40206MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-modules-extra
NoYesNov 12, 2025
CVE-2025-40210MEDIUM5.1
  • Linux KernelLinux Kernel
  • kernel-rt-64k-modules
NoYesNov 21, 2025
CVE-2025-40212N/AN/A
  • Linux KernelLinux Kernel
  • linux-azure-6.14
NoYesNov 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management