Answer in brief
CVE-2025-37838 records a Unknown severity vulnerability in HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2025-37838 records a Unknown severity vulnerability in HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=df26d639e2f4628732a8da5a0f71e4e652ce809b <d03abc1c2b21324550fa71e12d53e7d3498e0af6 || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <4a8c29beb8a02b5a0a9d77d608aa14b6f88a6b86 || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <72972552d0d0bfeb2dec5daf343a19018db36ffa || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <d58493832e284f066e559b8da5ab20c15a2801d3 || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <58eb29dba712ab0f13af59ca2fe545f5ce360e78 || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <ae5a6a0b425e8f76a9f0677e50796e494e89b088 || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <834e602d0cc7c743bfce734fad4a46cefc0f9ab1 || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <4b4194c9a7a8f92db39e8e86c85f4fb12ebbec4f || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <e3f88665a78045fe35c7669d2926b8d97b892c11 | d03abc1c2b21324550fa71e12d53e7d3498e0af6, 4a8c29beb8a02b5a0a9d77d608aa14b6f88a6b86, 72972552d0d0bfeb2dec5daf343a19018db36ffa, d58493832e284f066e559b8da5ab20c15a2801d3, 58eb29dba712ab0f13af59ca2fe545f5ce360e78, ae5a6a0b425e8f76a9f0677e50796e494e89b088, 834e602d0cc7c743bfce734fad4a46cefc0f9ab1, 4b4194c9a7a8f92db39e8e86c85f4fb12ebbec4f, e3f88665a78045fe35c7669d2926b8d97b892c11 |
| Linux/Linuxgeneric | 4.8 | Not reported |
Published upstream
Apr 18, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition In the ssi_protocol_probe() function, &ssi->work is bound with ssip_xmit_work(), In ssip_pn_setup(), the ssip_pn_xmit() function within the ssip_pn_ops structure is capable of starting the work. If we remove the module which will call ssi_protocol_remove() to make a cleanup, it will free ssi through kfree(ssi), while the work mentioned above will be used. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | ssip_xmit_work ssi_protocol_remove | kfree(ssi); | | struct hsi_client *cl = ssi->cl; | // use ssi Fix it by ensuring that the work is canceled before proceeding with the cleanup in ssi_protocol_remove().
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=df26d639e2f4628732a8da5a0f71e4e652ce809b <d03abc1c2b21324550fa71e12d53e7d3498e0af6 || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <4a8c29beb8a02b5a0a9d77d608aa14b6f88a6b86 || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <72972552d0d0bfeb2dec5daf343a19018db36ffa || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <d58493832e284f066e559b8da5ab20c15a2801d3 || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <58eb29dba712ab0f13af59ca2fe545f5ce360e78 || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <ae5a6a0b425e8f76a9f0677e50796e494e89b088 || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <834e602d0cc7c743bfce734fad4a46cefc0f9ab1 || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <4b4194c9a7a8f92db39e8e86c85f4fb12ebbec4f || >=df26d639e2f4628732a8da5a0f71e4e652ce809b <e3f88665a78045fe35c7669d2926b8d97b892c11 | d03abc1c2b21324550fa71e12d53e7d3498e0af6, 4a8c29beb8a02b5a0a9d77d608aa14b6f88a6b86, 72972552d0d0bfeb2dec5daf343a19018db36ffa, d58493832e284f066e559b8da5ab20c15a2801d3, 58eb29dba712ab0f13af59ca2fe545f5ce360e78, ae5a6a0b425e8f76a9f0677e50796e494e89b088, 834e602d0cc7c743bfce734fad4a46cefc0f9ab1, 4b4194c9a7a8f92db39e8e86c85f4fb12ebbec4f, e3f88665a78045fe35c7669d2926b8d97b892c11 |
| Linux/Linuxgeneric | 4.8 | Not reported |
Published upstream
Apr 18, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: HSI: ssi_protocol: Fix use after free vulnerability in ssi_protocol Driver Due to Race Condition In the ssi_protocol_probe() function, &ssi->work is bound with ssip_xmit_work(), In ssip_pn_setup(), the ssip_pn_xmit() function within the ssip_pn_ops structure is capable of starting the work. If we remove the module which will call ssi_protocol_remove() to make a cleanup, it will free ssi through kfree(ssi), while the work mentioned above will be used. The sequence of operations that may lead to a UAF bug is as follows: CPU0 CPU1 | ssip_xmit_work ssi_protocol_remove | kfree(ssi); | | struct hsi_client *cl = ssi->cl; | // use ssi Fix it by ensuring that the work is canceled before proceeding with the cleanup in ssi_protocol_remove().
Quoted source text, attributed separately from HOL analysis.