CVE-2025-37990

Updated: 2025-12-28 03:48:46.218209

Description:

In the Linux kernel, the following vulnerability has been resolved: wifi: brcm80211: fmac: Add error handling for brcmf_usb_dl_writeimage() The function brcmf_usb_dl_writeimage() calls the function brcmf_usb_dl_cmd() but dose not check its return value. The 'state.state' and the 'state.bytes' are uninitialized if the function brcmf_usb_dl_cmd() fails. It is dangerous to use uninitialized variables in the conditions. Add error handling for brcmf_usb_dl_cmd() to jump to error handling path if the brcmf_usb_dl_cmd() fails and the 'state.state' and the 'state.bytes' are uninitialized. Improve the error message to report more detailed error information.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU kernel 5.14.0 5.5 MEDIUM Needs Triage 2025-12-28 07:58:06
CentOS 7 ELS kernel 3.10.0 5.5 MEDIUM Needs Triage 2025-12-28 07:58:07
CentOS 8.4 ELS kernel 4.18.0 5.5 MEDIUM Needs Triage 2025-12-28 07:58:03
CentOS 8.5 ELS kernel 4.18.0 5.5 MEDIUM Needs Triage 2025-12-28 07:58:02
CentOS Stream 8 ELS kernel 4.18.0 5.5 MEDIUM Needs Triage 2025-12-28 07:58:09
CloudLinux 7 ELS kernel 3.10.0 5.5 MEDIUM Needs Triage 2025-12-28 07:58:11
Oracle Linux 7 ELS kernel 3.10.0 5.5 MEDIUM Needs Triage 2025-12-28 07:58:10
Oracle Linux 7 ELS kernel-uek 5.4.17 5.5 MEDIUM Released CLSA-2025:1757963029 2025-09-16 11:20:17
RHEL 7 ELS kernel 3.10.0 5.5 MEDIUM Needs Triage 2025-12-28 07:58:12
TuxCare 9.6 ESU kernel 5.14.0 5.5 MEDIUM Needs Triage 2025-12-28 07:58:04
Total: 14