Answer in brief
CVE-2025-37984 records a Unknown severity vulnerability in crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=55779f26eab9af12474a447001bd17070f055712 <f02f0218be412cff1c844addf58e002071be298b || >=c6ab5c915da460c0397960af3c308386c3f3247b <f2133b849ff273abddb6da622daddd8f6f6fa448 || >=c6ab5c915da460c0397960af3c308386c3f3247b <921b8167f10708e38080f84e195cdc68a7a561f1 || >=c6ab5c915da460c0397960af3c308386c3f3247b <b16510a530d1e6ab9683f04f8fb34f2e0f538275 || >=6.6.70 <6.6.99 | f02f0218be412cff1c844addf58e002071be298b, f2133b849ff273abddb6da622daddd8f6f6fa448, 921b8167f10708e38080f84e195cdc68a7a561f1, b16510a530d1e6ab9683f04f8fb34f2e0f538275, 6.6.99 |
| Linux/Linuxgeneric | 6.10 | Not reported |
Published upstream
May 20, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() Herbert notes that DIV_ROUND_UP() may overflow unnecessarily if an ecdsa implementation's ->key_size() callback returns an unusually large value. Herbert instead suggests (for a division by 8): X / 8 + !!(X & 7) Based on this formula, introduce a generic DIV_ROUND_UP_POW2() macro and use it in lieu of DIV_ROUND_UP() for ->key_size() return values. Additionally, use the macro in ecc_digits_from_bytes(), whose "nbytes" parameter is a ->key_size() return value in some instances, or a user-specified ASN.1 length in the case of ecdsa_get_signature_rs().
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2025-37984 records a Unknown severity vulnerability in crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP(). The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=55779f26eab9af12474a447001bd17070f055712 <f02f0218be412cff1c844addf58e002071be298b || >=c6ab5c915da460c0397960af3c308386c3f3247b <f2133b849ff273abddb6da622daddd8f6f6fa448 || >=c6ab5c915da460c0397960af3c308386c3f3247b <921b8167f10708e38080f84e195cdc68a7a561f1 || >=c6ab5c915da460c0397960af3c308386c3f3247b <b16510a530d1e6ab9683f04f8fb34f2e0f538275 || >=6.6.70 <6.6.99 | f02f0218be412cff1c844addf58e002071be298b, f2133b849ff273abddb6da622daddd8f6f6fa448, 921b8167f10708e38080f84e195cdc68a7a561f1, b16510a530d1e6ab9683f04f8fb34f2e0f538275, 6.6.99 |
| Linux/Linuxgeneric | 6.10 | Not reported |
Published upstream
May 20, 2025
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: crypto: ecdsa - Harden against integer overflows in DIV_ROUND_UP() Herbert notes that DIV_ROUND_UP() may overflow unnecessarily if an ecdsa implementation's ->key_size() callback returns an unusually large value. Herbert instead suggests (for a division by 8): X / 8 + !!(X & 7) Based on this formula, introduce a generic DIV_ROUND_UP_POW2() macro and use it in lieu of DIV_ROUND_UP() for ->key_size() return values. Additionally, use the macro in ecc_digits_from_bytes(), whose "nbytes" parameter is a ->key_size() return value in some instances, or a user-specified ASN.1 length in the case of ecdsa_get_signature_rs().
Quoted source text, attributed separately from HOL analysis.