CVE-2025-37751 is a vulnerability in the Linux kernel affecting x86 CPUs, specifically an issue where the erratum_1386_microcode array lacks a NULL terminator, causing code to read beyond its bounds. This local vulnerability has a CVSS score of 5.5 (Medium), indicating a low attack complexity and privilege requirement, with a potential impact of high availability loss but no confidentiality or integrity compromise. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion beyond a single security update notice.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.14, < 6.14.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.15CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.