A flaw tracked as CVE-2025-37861 affects the Linux kernel's scsi: mpi3mr driver, where improper synchronization between the reset thread and the task management thread can expose an invalid reply queue ID of 0xFFFF during controller reset. That race can cause the task management path to reference unallocated memory and trigger a kernel crash, making the issue a denial-of-service risk. Red Hat rated the bug Moderate with a CVSS 6.3, while NVD and CVE.org scored it 7.8; Red Hat said exploitation requires local access with a special group privilege and noted no integrity impact in the known use case.
Upstream Linux fixed the bug by adding an io_admin_reset_sync flag to coordinate reset, I/O, and admin thread access to reply queues, block processing during reset, and mark the controller unrecoverable if synchronization does not complete within 10 seconds. The Linux kernel CVE team said the issue is resolved in versions 6.12.24, 6.13.12, 6.14.3, and 6.15-rc1, and advised users to move to the latest stable kernel release. Red Hat also shipped fixes across multiple Red Hat Enterprise Linux 9 variants, including kernel-rt updates in advisory RHSA-2026:3358, while stating RHEL 10 is affected and RHEL 6 and RHEL 7 kernel packages are not affected because the vulnerable code is absent.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat lists CVE-2025-37861 as fixed in Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions kernel-rt via RHSA-2026:14137. The Red Hat CVE record states this advisory was released on 2026-05-06.
Red Hat lists CVE-2025-37861 as fixed in Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions kernel via RHSA-2026:13936. The Red Hat CVE record states this advisory was released on 2026-05-06.
Red Hat lists CVE-2025-37861 as fixed in Red Hat Enterprise Linux 9.4 Extended Update Support through RHSA-2026:3692. The Red Hat CVE record states this advisory was released on 2026-03-04.
Red Hat lists CVE-2025-37861 as fixed in Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions kernel via RHSA-2026:3267. The Red Hat CVE record states this advisory was released on 2026-02-25.
On 2026-02-25, Red Hat issued RHSA-2026:3358, a Moderate security advisory for the kernel-rt package in Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions and Extended Life Cycle offerings. The advisory includes a fix for CVE-2025-37861 among multiple Linux kernel vulnerabilities.
Red Hat lists CVE-2025-37861 as fixed in Red Hat Enterprise Linux 9.6 Extended Update Support through advisory RHSA-2026:3088. The Red Hat CVE record states this advisory was released on 2026-02-23.
On 2025-05-09, the Linux kernel CVE team published an advisory for CVE-2025-37861 describing a race condition in the SCSI mpi3mr driver that can lead to access of unallocated memory and a crash. The advisory states the issue was fixed in kernel versions 6.12.24, 6.13.12, 6.14.3, and 6.15-rc1.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourceredhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.