CVE-2025-37968
Published: May 20, 2025
Modified: May 12, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: iio: light: opt3001: fix deadlock due to concurrent flag access The threaded IRQ function in this driver is reading the flag twice: once to lock a mutex and once to unlock it. Even though the code setting the flag is designed to prevent it, there are subtle cases where the flag could be true at the mutex_lock stage and false at the mutex_unlock stage. This results in the mutex not being unlocked, resulting in a deadlock. Fix it by making the opt3001_irq() code generally more robust, reading the flag into a variable and using the variable value at both stages.
| Vendor | Product | Versions |
|---|---|---|
Linux | Linux | affected 94a9b7b1809f56cfaa080e70ec49b6979563a237 - < a9c56ccb7cddfca754291fb24b108a5350a5fbe9affected 94a9b7b1809f56cfaa080e70ec49b6979563a237 - < 957e8be112636d9bc692917286e81e54bd87deccaffected 94a9b7b1809f56cfaa080e70ec49b6979563a237 - < 1d7def97e7eb65865ccc01bbdf4eb9e6bbe8a5b5affected 94a9b7b1809f56cfaa080e70ec49b6979563a237 - < 748ebd8e61d0bc182c331b8df3887af7285c8a8faffected 94a9b7b1809f56cfaa080e70ec49b6979563a237 - < e791bf216c9e236b34dabf514ec0ede140cca719+3 more versions |
Linux | Linux | affected 4.3unaffected 0 - < 4.3unaffected 5.4.299 - <= 5.4.*unaffected 5.10.243 - <= 5.10.*unaffected 5.15.192 - <= 5.15.*+5 more versions |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now