CVE-2025-37977

MEDIUM

Linux Kernel 5.16-6.12.25, 6.13-6.14.3, 6.15 - Denial of Service via UFS DMA Coherence Configuration

Title source: llm
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: exynos: Disable iocc if dma-coherent property isn't set If dma-coherent property isn't set then descriptors are non-cacheable and the iocc shareability bits should be disabled. Without this UFS can end up in an incompatible configuration and suffer from random cache related stability issues.

Scores

CVSS v3 5.5
EPSS 0.0015
EPSS Percentile 4.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (12)
linux/Kernel 5.16.0 - 6.12.26linux
linux/Kernel 6.13.0 - 6.14.4linux
Linux/Linux < 5.16
Linux/Linux 5.16
Linux/Linux 6.12.26 - 6.12.*
Linux/Linux 6.14.4 - 6.14.*
Linux/Linux 6.15
Linux/Linux cc52e15397cc5dc773d3c6792b98352d3209f93f - 869749e48115ef944eeabec8e84138908471fa51
Linux/Linux cc52e15397cc5dc773d3c6792b98352d3209f93f - f0c6728a6f2e269ebb234a9b5bb6c2c24aafeb51
Linux/Linux cc52e15397cc5dc773d3c6792b98352d3209f93f - f92bb7436802f8eb7ee72dc911a33c8897fde366
... and 2 more
Published May 20, 2025
Tracked Since Feb 18, 2026