Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      CodeSOD: Across the 4th Dimension

      September 25, 2025

      Cursor vs GitHub Copilot (2025): Which AI Platform Wins for Your Node.js Dev Team?

      September 25, 2025

      NuGet adds support for Trusted Publishing

      September 25, 2025

      AWS launches IDE extension for building browser automation agents

      September 25, 2025

      Distribution Release: Kali Linux 2025.3

      September 23, 2025

      Distribution Release: SysLinuxOS 13

      September 23, 2025

      Development Release: MX Linux 25 Beta 1

      September 22, 2025

      DistroWatch Weekly, Issue 1140

      September 21, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      Beyond Denial: How AI Concierge Services Can Transform Healthcare from Reactive to Proactive

      September 25, 2025
      Recent

      Beyond Denial: How AI Concierge Services Can Transform Healthcare from Reactive to Proactive

      September 25, 2025

      IDC ServiceScape for Microsoft Power Apps Low-Code/No-Code Custom Application Development Services

      September 25, 2025

      A Stream-Oriented UI library for interactive web applications

      September 24, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      FOSS Weekly #25.39: Kill Switch Phones, LMDE 7, Zorin OS 18 Beta, Polybar, Apt History and More Linux Stuff

      September 25, 2025
      Recent

      FOSS Weekly #25.39: Kill Switch Phones, LMDE 7, Zorin OS 18 Beta, Polybar, Apt History and More Linux Stuff

      September 25, 2025

      Distribution Release: Kali Linux 2025.3

      September 23, 2025

      Distribution Release: SysLinuxOS 13

      September 23, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Security»Common Vulnerabilities and Exposures (CVEs)»CVE-2025-37791 – Dell PowerEdge ethtool Stack Corruption Vulnerability

    CVE-2025-37791 – Dell PowerEdge ethtool Stack Corruption Vulnerability

    May 1, 2025

    CVE ID : CVE-2025-37791

    Published : May 1, 2025, 2:15 p.m. | 1 hour, 10 minutes ago

    Description : In the Linux kernel, the following vulnerability has been resolved:

    ethtool: cmis_cdb: use correct rpl size in ethtool_cmis_module_poll()

    rpl is passed as a pointer to ethtool_cmis_module_poll(), so the correct
    size of rpl is sizeof(*rpl) which should be just 1 byte. Using the
    pointer size instead can cause stack corruption:

    Kernel panic – not syncing: stack-protector: Kernel stack is corrupted in: ethtool_cmis_wait_for_cond+0xf4/0x100
    CPU: 72 UID: 0 PID: 4440 Comm: kworker/72:2 Kdump: loaded Tainted: G OE 6.11.0 #24
    Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE
    Hardware name: Dell Inc. PowerEdge R760/04GWWM, BIOS 1.6.6 09/20/2023
    Workqueue: events module_flash_fw_work
    Call Trace:

    panic+0x339/0x360
    ? ethtool_cmis_wait_for_cond+0xf4/0x100
    ? __pfx_status_success+0x10/0x10
    ? __pfx_status_fail+0x10/0x10
    __stack_chk_fail+0x10/0x10
    ethtool_cmis_wait_for_cond+0xf4/0x100
    ethtool_cmis_cdb_execute_cmd+0x1fc/0x330
    ? __pfx_status_fail+0x10/0x10
    cmis_cdb_module_features_get+0x6d/0xd0
    ethtool_cmis_cdb_init+0x8a/0xd0
    ethtool_cmis_fw_update+0x46/0x1d0
    module_flash_fw_work+0x17/0xa0
    process_one_work+0x179/0x390
    worker_thread+0x239/0x340
    ? __pfx_worker_thread+0x10/0x10
    kthread+0xcc/0x100
    ? __pfx_kthread+0x10/0x10
    ret_from_fork+0x2d/0x50
    ? __pfx_kthread+0x10/0x10
    ret_from_fork_asm+0x1a/0x30

    Severity: 0.0 | NA

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleCVE-2025-37792 – Linux Bluetooth btrtl NULL Pointer Dereference Vulnerability
    Next Article CVE-2025-37790 – “Linux Net MCTP Socket RCU Free Vulnerability”

    Related Posts

    Development

    Cursor AI Code Editor Flaw Enables Silent Code Execution via Malicious Repositories

    September 14, 2025
    Development

    Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass

    September 14, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-8801 – Open5GS Denial of Service Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    I’m upgrading to these magnetic headphones and their incredibly fun sound, but they’re less accessible than what I had

    News & Updates

    Custom Object Casting in Laravel Models

    Development

    Microsoft Edge unlocks background YouTube playback on Android — no Premium needed

    News & Updates

    Highlights

    CVE-2025-46729 – Julmud/phpDVDProfiler Cross-Site Scripting Vulnerability

    May 12, 2025

    CVE ID : CVE-2025-46729

    Published : May 12, 2025, 11:15 a.m. | 1 hour, 25 minutes ago

    Description : julmud/phpDVDProfiler is an adoption of the defunct phpDVDProfiler project, which allows users to display on the web their DVD collections maintained with Invelos’s DVDProfiler software. Starting in v_20230807 and prior to v_20250511, cross-site scripting in the search function. v_20250511 contains a patch for the issue.

    Severity: 0.0 | NA

    Visit the link for more details, such as CVSS details, affected products, timeline, and more…

    CVE-2023-32246 – Linux Kernel – Ksmbd RCU Callback Racy Unload Vulnerability

    August 16, 2025

    Amazon Aurora Global Database introduces support for up to 10 secondary Regions

    May 22, 2025

    CVE-2025-6849 – Simple Forum Cross-Site Scripting (XSS) Vulnerability

    June 29, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.