CVE-2025-37849General(debian / debian_linux)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Tear down vGIC on failed vCPU creation If kvm_arch_vcpu_create() fails to share the vCPU page with the hypervisor, we propagate the error back to the ioctl but leave the vGIC vCPU data initialised. Note only does this leak the corresponding memory when the vCPU is destroyed but it can also lead to use-after-free if the redistributor device handling tries to walk into the vCPU. Add the missing cleanup to kvm_arch_vcpu_create(), ensuring that the vGIC vCPU structures are destroyed on error.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • linux_kernel

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
debian_linuxlinux_kernel

1 version affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-11: 1Technical Details · 2026-08-11: 108-11
Signal classification1 categories
General
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Windows Forum@windowsforum
    General

    🛡️ CVE-2025-37849 isn’t a Windows flaw—it’s an Arm64 Linux KVM host bug. The NVD’s broad CPE label makes it look scarier than it is. Virtualization nuance: still undefeated. https://windowsforum.com/security-alerts.84/cve-2025-37849-affects-arm64-kvm-hosts-not-windows.442310/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #VirtualizationSecurity #LinuxKernelSecurity #Arm64Kvm #Cve202537849 https://t.co/mhHeyFC8gj

    Post summary

    The post clarifies that CVE‑2025‑37849 is an Arm64 Linux KVM host bug, not a Windows flaw, and notes that NVD’s broad CPE labeling may exaggerate its severity.

    0000044
    1.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
OSlinuxlinux_kernel---

Explore more