Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-37993

15
FAUCET Score

CVE-2025-37993 is a medium-severity vulnerability in the Linux kernel's CAN bus driver (m_can), affecting the linux and linux_kernel products. It stems from an uninitialized spin lock (tx_handling_spinlock), leading to kernel panics and system unavailability when CAN frames are sent. The vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring low privileges, and resulting in high availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion or media coverage, suggesting a low immediate threat.

Impacted Technologies

VendorProductVersion(s)CPE
>= 6.9, < 6.12.29CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 6.13, < 6.14.7CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.15CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.15:rc1:*:*:*:*:*:*
6.15CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.15:rc2:*:*:*:*:*:*
6.15CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:6.15:rc3:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.15%
Probability of exploitation in next 30 days
EPSS Percentile
4.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0015 is in the 27th percentile among its peer group of 15,940 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: kernel

Vendor Advisories (1)

redhatCVE-2025-37993Moderate

kernel: can: m_can: m_can_class_allocate_dev(): initialize spin lock on device probe

May 29, 2025

References

git.kernel.org / stable/c/2ecce25ea296f328d79070ee36229a15aeeb7aca
Patch
git.kernel.org / stable/c/7d5379cfecfdd665e4206bc4f19824656388779f
Patch
git.kernel.org / stable/c/dcaeeb8ae84c5506ebc574732838264f3887738c
Patch