Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-37784

17
FAUCET Score

CVE-2025-37784 is a NULL pointer dereference vulnerability in the Linux kernel's ICSS IEP driver, specifically affecting the handling of perout and PPS enable states. This medium-severity vulnerability (CVSS 5.5) can lead to a denial of service (A:H) on affected systems, requiring local access and low privileges (AV:L/PR:L). There is no evidence of active exploitation, and no public exploit code is currently available. Despite its low EPSS score, the vulnerability has garnered some community discussion and media coverage, primarily from Ubuntu security advisories.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.6.70, < 6.6.88CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.12.9, < 6.12.25CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.13.1, < 6.14.4CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.13CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.13:-:*:*:*:*:*:*
6.13CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.13:rc6:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
6.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 35th percentile among its peer group of 15,940 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

ubuntupatch availablevia ubuntu_usn
Product: linux-xilinx (noble)Fixed in: 6.8.0-1023.24
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm-6.8 (jammy)Fixed in: 6.8.0-1044.44~22.04.1
ubuntupatch availablevia ubuntu_usn
Product: linux-ibm (noble)Fixed in: 6.8.0-1044.44
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-fips (noble)Fixed in: 6.8.0-1046.52+fips1
ubuntupatch availablevia ubuntu_usn
Product: linux-azure (noble)Fixed in: 6.8.0-1046.52
ubuntupatch availablevia ubuntu_usn
Product: linux-azure-6.8 (jammy)Fixed in: 6.8.0-1051.57~22.04.1

Vendor Advisories (6)

ubuntuUSN-8126-1

Linux kernel (Azure) vulnerabilities

Mar 25, 2026
ubuntuUSN-8074-2

Linux kernel (Azure FIPS) vulnerabilities

Mar 4, 2026
ubuntuUSN-8074-1

Linux kernel (Azure) vulnerabilities

Mar 4, 2026
ubuntuUSN-8052-2

Linux kernel (Xilinx) vulnerabilities

Feb 24, 2026
ubuntuUSN-8028-8

Linux kernel (IBM) vulnerabilities

Feb 24, 2026
redhatCVE-2025-37784

kernel: net: ti: icss-iep: Fix possible NULL pointer dereference for perout request

May 1, 2025

References

git.kernel.org / stable/c/7349c9e9979333abfce42da5f9025598083b59c9
Patch
git.kernel.org / stable/c/7891619d21f07a88e0275d6d43db74035aa74f69
Patch
git.kernel.org / stable/c/da5035d7aeadcfa44096dd34689bfed6c657f559
Patch
git.kernel.org / stable/c/eeec66327001421531b3fb1a2ac32efc8a2493b0
Patch