boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2025-37893MEDIUM
Linux Linux — LoongArch: BPF: Fix off-by-one error in build_prologue()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  N  N  H    5.5   .0026   17.9     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    5dc615520c4dfb358245680f1904bad61116648e –  —
  Linux    6.1 –                                       6.6.87
TIMELINE
  Apr 16  Reserved by Linux
  Apr 18  Published (CNA: Linux)
  Jul 30  RESCORED — CVE-2025-37893 (Linux). CVSS 7.8 → 5.5 (NVD).
CWE-193 · CNA: Linux · CVSS v3.1 · 5 references · NVD status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: LoongArch: BPF: Fix off-by-one error in build_prologue() Vincent reported that running BPF progs with tailcalls on LoongArch causes kernel hard lockup. Debugging the issues shows that the JITed image missing a jirl instruction at the end of the epilogue. There are two passes in JIT compiling, the first pass set the flags and the second pass generates JIT code based on those flags. With BPF progs mixing bpf2bpf and tailcalls, build_prologue() generates N insns in the first pass and then generates N+1 insns in the second pass. This makes epilogue_offset off by one and we will jump to some unexpected insn and cause lockup. Fix this by inserting a nop insn.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
April 16, 2025ReservedReserved by Linux
April 18, 2025PublishedPublished (CNA: Linux)
July 30, 2026RESCOREDRESCORED — CVE-2025-37893 (Linux). CVSS 7.8 → 5.5 (NVD).

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
LinuxLinux5dc615520c4dfb358245680f1904bad61116648e
LinuxLinux6.16.6.87

Weaknesses

CWE-193

References (5)

Related

Authoritative record: CVE-2025-37893 at cve.org

Vendors: linux

Weaknesses: CWE-193

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2025-37893 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.