CVE-2025-37812

Updated: 2025-11-19 04:40:32.629656

Description:

In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: Fix deadlock when using NCM gadget The cdns3 driver has the same NCM deadlock as fixed in cdnsp by commit 58f2fcb3a845 ("usb: cdnsp: Fix deadlock issue during using NCM gadget"). Under PREEMPT_RT the deadlock can be readily triggered by heavy network traffic, for example using "iperf --bidir" over NCM ethernet link. The deadlock occurs because the threaded interrupt handler gets preempted by a softirq, but both are protected by the same spinlock. Prevent deadlock by disabling softirq during threaded irq handler.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Needs Triage 2025-11-25 02:00:25
Oracle Linux 7 ELS kernel-uek 5.4.17 5.5 MEDIUM Released CLSA-2025:1757963029 2025-09-16 11:20:46
TuxCare 9.6 ESU kernel 5.14.0 5.5 MEDIUM Ignored 2025-12-03 00:22:43 Deprioritize: the bug only manifests on systems that 1) use the Cadence USB3 (cdns3) controller in U...
Ubuntu 20.04 ELS linux 5.4.0 5.5 MEDIUM Needs Triage 2025-11-24 16:23:59