CVE-2025-37846

EUVD-2025-14146
In the Linux kernel, the following vulnerability has been resolved:

arm64: mops: Do not dereference src reg for a set operation

The source register is not used for SET* and reading it can result in
a UBSAN out-of-bounds array access error, specifically when the MOPS
exception is taken from a SET* sequence with XZR (reg 31) as the
source. Architecturally this is the only case where a src/dst/size
field in the ESR can be reported as 31.

Prior to 2de451a329cf662b the code in do_el0_mops() was benign as the
use of pt_regs_read_reg() prevented the out-of-bounds access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
6.7 ≤
𝑥
< 6.12.24
linuxlinux_kernel
6.13 ≤
𝑥
< 6.13.12
linuxlinux_kernel
6.14 ≤
𝑥
< 6.14.3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bookworm
6.1.170-3
fixed
bookworm (security)
6.1.174-1
fixed
bullseye
5.10.223-1
fixed
bullseye (security)
5.10.257-1
fixed
forky
7.0.10-1
fixed
sid
7.0.10-1
fixed
trixie
6.12.86-1
fixed
trixie (security)
6.12.90-2
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
kernel-64kb
suse enterprise server 15 SP3
5.3.18-150300.59.207.1
fixed
kernel-default
suse enterprise server 15 SP2
5.3.18-150200.24.230.1
fixed
suse enterprise server 15 SP3
5.3.18-150300.59.207.1
fixed
kernel-default-base
suse enterprise server 15 SP2
5.3.18-150200.24.230.1.150200.9.124.1
fixed
suse enterprise server 15 SP3
5.3.18-150300.59.207.1.150300.18.124.1
fixed
kernel-docs
suse enterprise server 15 SP2
5.3.18-150200.24.230.1
fixed
suse enterprise server 15 SP3
5.3.18-150300.59.207.1
fixed
kernel-macros
suse enterprise server 15 SP2
5.3.18-150200.24.230.1
fixed
suse enterprise server 15 SP3
5.3.18-150300.59.207.1
fixed
kernel-obs-build
suse enterprise server 15 SP2
5.3.18-150200.24.230.1
fixed
suse enterprise server 15 SP3
5.3.18-150300.59.207.1
fixed
kernel-preempt
suse enterprise server 15 SP2
5.3.18-150200.24.230.1
fixed
suse enterprise server 15 SP3
5.3.18-150300.59.207.1
fixed
kernel-source
suse enterprise server 15 SP2
5.3.18-150200.24.230.1
fixed
suse enterprise server 15 SP3
5.3.18-150300.59.207.1
fixed
kernel-syms
suse enterprise server 15 SP2
5.3.18-150200.24.230.1
fixed
suse enterprise server 15 SP3
5.3.18-150300.59.207.1
fixed
kernel-zfcpdump
suse enterprise server 15 SP3
5.3.18-150300.59.207.1
fixed
reiserfs-kmp-default
suse enterprise server 15 SP2
5.3.18-150200.24.230.1
fixed
suse enterprise server 15 SP3
5.3.18-150300.59.207.1
fixed