{"id":"DEBIAN-CVE-2025-37917","details":"In the Linux kernel, the following vulnerability has been resolved:  net: ethernet: mtk-star-emac: fix spinlock recursion issues on rx/tx poll  Use spin_lock_irqsave and spin_unlock_irqrestore instead of spin_lock and spin_unlock in mtk_star_emac driver to avoid spinlock recursion occurrence that can happen when enabling the DMA interrupts again in rx/tx poll.  ``` BUG: spinlock recursion on CPU#0, swapper/0/0  lock: 0xffff00000db9cf20, .magic: dead4ead, .owner: swapper/0/0,     .owner_cpu: 0 CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted     6.15.0-rc2-next-20250417-00001-gf6a27738686c-dirty #28 PREEMPT Hardware name: MediaTek MT8365 Open Platform EVK (DT) Call trace:  show_stack+0x18/0x24 (C)  dump_stack_lvl+0x60/0x80  dump_stack+0x18/0x24  spin_dump+0x78/0x88  do_raw_spin_lock+0x11c/0x120  _raw_spin_lock+0x20/0x2c  mtk_star_handle_irq+0xc0/0x22c [mtk_star_emac]  __handle_irq_event_percpu+0x48/0x140  handle_irq_event+0x4c/0xb0  handle_fasteoi_irq+0xa0/0x1bc  handle_irq_desc+0x34/0x58  generic_handle_domain_irq+0x1c/0x28  gic_handle_irq+0x4c/0x120  do_interrupt_handler+0x50/0x84  el1_interrupt+0x34/0x68  el1h_64_irq_handler+0x18/0x24  el1h_64_irq+0x6c/0x70  regmap_mmio_read32le+0xc/0x20 (P)  _regmap_bus_reg_read+0x6c/0xac  _regmap_read+0x60/0xdc  regmap_read+0x4c/0x80  mtk_star_rx_poll+0x2f4/0x39c [mtk_star_emac]  __napi_poll+0x38/0x188  net_rx_action+0x164/0x2c0  handle_softirqs+0x100/0x244  __do_softirq+0x14/0x20  ____do_softirq+0x10/0x20  call_on_irq_stack+0x24/0x64  do_softirq_own_stack+0x1c/0x40  __irq_exit_rcu+0xd4/0x10c  irq_exit_rcu+0x10/0x1c  el1_interrupt+0x38/0x68  el1h_64_irq_handler+0x18/0x24  el1h_64_irq+0x6c/0x70  cpuidle_enter_state+0xac/0x320 (P)  cpuidle_enter+0x38/0x50  do_idle+0x1e4/0x260  cpu_startup_entry+0x34/0x3c  rest_init+0xdc/0xe0  console_on_rootfs+0x0/0x6c  __primary_switched+0x88/0x90 ```","modified":"2026-09-01T16:06:13.183039856Z","published":"2025-05-20T16:15:28.273Z","upstream":["CVE-2025-37917"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-37917"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.140-1"}]}],"versions":["6.1.106-1","6.1.106-2","6.1.106-3","6.1.112-1","6.1.115-1","6.1.119-1","6.1.123-1","6.1.124-1","6.1.128-1","6.1.129-1","6.1.133-1","6.1.135-1","6.1.137-1","6.1.139-1","6.1.27-1","6.1.37-1","6.1.38-1","6.1.38-2","6.1.38-2~bpo11+1","6.1.38-3","6.1.38-4","6.1.38-4~bpo11+1","6.1.52-1","6.1.55-1","6.1.55-1~bpo11+1","6.1.64-1","6.1.66-1","6.1.67-1","6.1.69-1","6.1.69-1~bpo11+1","6.1.76-1","6.1.76-1~bpo11+1","6.1.82-1","6.1.85-1","6.1.90-1","6.1.90-1~bpo11+1","6.1.94-1","6.1.94-1~bpo11+1","6.1.98-1","6.1.99-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-37917.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.29-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-37917.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.12.29-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-37917.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}