CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-37933: octeon_ep: Fix host hang issue during device reboot

Description

In the Linux kernel, the following vulnerability has been resolved:

octeon_ep: Fix host hang issue during device reboot

When the host loses heartbeat messages from the device,
the driver calls the device-specific ndo_stop function,
which frees the resources. If the driver is unloaded in
this scenario, it calls ndo_stop again, attempting to free
resources that have already been freed, leading to a host
hang issue. To resolve this, dev_close should be called
instead of the device-specific stop function.dev_close
internally calls ndo_stop to stop the network interface
and performs additional cleanup tasks. During the driver
unload process, if the device is already down, ndo_stop
is not called.

Classification

CVE ID: CVE-2025-37933

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 4.6% (scored less or equal to compared to others)

EPSS Date: 2025-06-18 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-37933
https://git.kernel.org/stable/c/7e1ca1bed3f66e00377f7d2147be390144924276
https://git.kernel.org/stable/c/c8d788f800f83b94d9db8b3dacc1d26be38a6ef4
https://git.kernel.org/stable/c/6d1052423518e7d0aece9af5e77bbc324face8f1
https://git.kernel.org/stable/c/34f42736b325287a7b2ce37e415838f539767bda

Timeline