x86/cpu: Avoid running off the end of an AMD erratum table
Published May 1, 2025
7.1
HIGHCVSS 3.1
EPSS 0.16%
Description
The NULL array terminator at the end of erratum_1386_microcode was removed during the switch from x86_cpu_desc to x86_cpu_id. This causes readers to run off the end of the array.
Replace the NULL.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.14StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.14
- Version 6.14.3StatusunaffectedConstraints<=6.14.*
- Version 6.15StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 6.14 · < 6.14.3
- 6.15
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Out of support scope
Red Hat Enterprise Linux 7
kernel-rt
Out of support scope
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Out of support scope | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2 other sources (CVE.org, Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.16% (0.00164) | 5.07th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.13% (0.00131) | 3.00th | v5 (v2026.06.15) |
| May 2, 2025 | 0.02% (0.00018) | 3.43th | v4 (v2025.03.14) |
References (7)
- https://access.redhat.com/security/cve/CVE-2025-37751 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2363351 Issue Tracking
- https://git.kernel.org/stable/c/1b518f73f1b6f59e083ec33dea22d9a1a275a970 Patch
- https://git.kernel.org/stable/c/f0df00ebc57f803603f2a2e0df197e51f06fbe90 Patch
- https://lore.kernel.org/linux-cve-announce/2025050137-CVE-2025-37751-8ed2@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2025-37751
- https://www.cve.org/CVERecord?id=CVE-2025-37751
Change history (0)
No recorded changes yet.