CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-37977: scsi: ufs: exynos: Disable iocc if dma-coherent property isn't set

Description

In the Linux kernel, the following vulnerability has been resolved:

scsi: ufs: exynos: Disable iocc if dma-coherent property isn't set

If dma-coherent property isn't set then descriptors are non-cacheable
and the iocc shareability bits should be disabled. Without this UFS can
end up in an incompatible configuration and suffer from random cache
related stability issues.

Classification

CVE ID: CVE-2025-37977

Affected Products

Vendor: Linux

Product: Linux

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.02% (probability of being exploited)

EPSS Percentile: 4.26% (scored less or equal to compared to others)

EPSS Date: 2025-06-18 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-37977
https://git.kernel.org/stable/c/869749e48115ef944eeabec8e84138908471fa51
https://git.kernel.org/stable/c/f0c6728a6f2e269ebb234a9b5bb6c2c24aafeb51
https://git.kernel.org/stable/c/f92bb7436802f8eb7ee72dc911a33c8897fde366

Timeline