CVE-2025-37892

Updated: 2026-02-27 03:35:26.316585

Description:

In the Linux kernel, the following vulnerability has been resolved: mtd: inftlcore: Add error check for inftl_read_oob() In INFTL_findwriteunit(), the return value of inftl_read_oob() need to be checked. A proper implementation can be found in INFTL_deleteblock(). The status will be set as SECTOR_IGNORE to break from the while-loop correctly if the inftl_read_oob() fails.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 7.8 HIGH Not Vulnerable 2025-11-25 20:52:44 CONFIG_INFTL is not set
CentOS 6 ELS kernel 2.6.32 7.8 HIGH Released CLSA-2026:1768669128 2026-01-28 13:11:23
CentOS 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2025-12-08 17:37:04 Not affected: the vulnerable code path exists only in the MTD INFTL subsystem (drivers/mtd/inftlcore...
CentOS 8.4 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2025-12-08 17:37:06 Not affected: CVE-2025-37892 only applies to the INFTL driver in the Linux MTD subsystem and is reac...
CentOS 8.5 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2025-12-08 17:37:06 Not affected: CVE-2025-37892 only applies to the INFTL driver in the Linux MTD subsystem and is reac...
CentOS Stream 8 ELS kernel 4.18.0 7.8 HIGH Not Vulnerable 2025-12-03 19:07:07 Not affected: CVE-2025-37892 only applies to the INFTL driver in the Linux MTD subsystem and is reac...
CloudLinux 7 ELS kernel 3.10.0 7.8 HIGH Ignored 2025-12-27 05:16:24 CloudLinux 6 and 7 support is limited and provided on demand. We strongly recommend upgrading to Clo...
Oracle Linux 6 ELS kernel 2.6.32 7.8 HIGH Released CLSA-2026:1769610819 2026-01-28 21:33:23
Oracle Linux 7 ELS kernel 3.10.0 7.8 HIGH Not Vulnerable 2025-12-31 07:29:24 Not affected: the vulnerable code path exists only in the MTD INFTL subsystem (drivers/mtd/inftlcore...
Oracle Linux 7 ELS kernel-uek 5.4.17 7.8 HIGH Released CLSA-2025:1757963029 2025-09-16 11:20:27 Not affected: the vulnerable code path exists only in the MTD INFTL subsystem (drivers/mtd/inftlcore...
Total: 16