SB2025052190 - Input validation error in Linux kernel marvell octeon_ep driver
Published: May 21, 2025 Updated: May 21, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Input validation error (CVE-ID: CVE-2025-37933)
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation within the octep_hb_timeout_task() function in drivers/net/ethernet/marvell/octeon_ep/octep_main.c. A local user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/34f42736b325287a7b2ce37e415838f539767bda
- https://git.kernel.org/stable/c/6d1052423518e7d0aece9af5e77bbc324face8f1
- https://git.kernel.org/stable/c/7e1ca1bed3f66e00377f7d2147be390144924276
- https://git.kernel.org/stable/c/c8d788f800f83b94d9db8b3dacc1d26be38a6ef4
- https://mirrors.edge.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.12.28